Juniper Networks Junos OS
cpe:2.3:a:juniper:junos:*:*:*:*:*:*:*, +2 more
- < 22.4R3-S8
- >= 23.2, < 23.2R2-S3
- >= 23.4, < 23.4R2
A vulnerability in the FTP server of Juniper Networks Junos OS has been identified, allowing an unauthenticated, network-based attacker to bypass authentication and gain limited read-write access to files on the device. This issue arises when the FTP server is enabled and a user named 'ftp' or 'anonymous' is configured. In such cases, the user can log in without providing the correct password and access their home directory. This vulnerability affects all Junos OS versions prior to 22.4R3-S8, as well as 23.2 versions prior to 23.2R2-S3 and 23.4 versions prior to 23.4R2.
Exploitation of this vulnerability allows for authentication bypass, granting unauthorized users read-write access to files in the home directory of the 'ftp' or 'anonymous' user on the affected device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.