Security News > 2023 > August > Exploit released for Juniper firewall bugs allowing RCE attacks
Proof-of-concept exploit code has been publicly released for vulnerabilities in Juniper SRX firewalls that, when chained, can allow unauthenticated attackers to gain remote code execution in Juniper's JunOS on unpatched devices.
Juniper disclosed four medium-severity bugs in its EX switches and SRX firewalls and released security patches two weeks ago.
The security flaws were found in the PHP-based J-Web interface that admins can use to manage and configure Juniper devices on their networks.
WatchTowr Labs security researchers have since developed and released a proof-of-concept exploit that chains the SRX firewall flaws, a missing authentication for critical function vulnerability and a PHP external variable modification bug.
While Juniper has not provided any info on active exploitation of the security flaws in the wild, watchTowr Labs expects attackers to soon start targeting Juniper devices left unpatched in widescale attacks.
New PaperCut critical bug exposes unpatched servers to RCE attacks.
- CISA warns of actively exploited Juniper pre-auth RCE exploit chain (source)
- MATA malware framework exploits EDR in attacks on defense firms (source)
- VMware warns admins of public exploit for vRealize RCE flaw (source)
- Pro-Russia group exploits Roundcube zero-day in attacks on European government emails (source)
- Record-Breaking 100 Million RPS DDoS Attack Exploits HTTP/2 Rapid Reset Flaw (source)
- Side channel attacks take bite out of Apple silicon with iLeakage exploit (source)
- EleKtra-Leak Cryptojacking Attacks Exploit AWS IAM Credentials Exposed on GitHub (source)
- RCE exploit for Wyze Cam v3 publicly released, patch now (source)
- Hackers exploit recent F5 BIG-IP flaws in stealthy attacks (source)
- 3,000 Apache ActiveMQ servers vulnerable to RCE attacks exposed online (source)