Juniper Networks Junos Space Security Director Missing Authorization Vulnerability Allowing Metadata Manipulation

Vulnerability

A missing authorization vulnerability exists in Juniper Networks Junos Space Security Director, affecting all versions prior to 24.1R3 Patch V4. This vulnerability allows an unauthenticated, network-based attacker to read or modify metadata through the web interface. Altering this metadata could enable managed SRX Series devices to allow network traffic that should be blocked by policy, thereby circumventing established security measures. Notably, this issue does not impact managed cSRX Series devices.

Impact

Exploitation of this vulnerability could lead to unauthorized modification of metadata, allowing managed SRX Series devices to bypass security policies and permit blocked network traffic.

Added: Oct 9, 2025, 4:24 PM
Updated: Oct 9, 2025, 4:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.1
exploitability
7.0
remediation
7.7
relevance
0.7
threat
0.0
urgency
1.4
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.