CVE-2024-21620

High PUBLISHED

Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS

Juniper Networks · Junos OS

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
8.8 High

At a Glance

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. A specific invocation of the emit_debug_note method in webauth_operation.php will echo back the data it receives. This issue affects Juniper Networks Junos OS on SRX Series and EX Series: * All versions earlier than 20.4R3-S10; * 21.2 versions earlier than 21.2R3-S8; * 21.4 versions earlier than 21.4R3-S6; * 22.1 versions earlier than 22.1R3-S5; * 22.2 versions earlier than 22.2R3-S3; * 22.3 versions earlier than 22.3R3-S2; * 22.4 versions earlier than 22.4R3-S1; * 23.2 versions earlier than 23.2R2; * 23.4 versions earlier than 23.4R2.

CVE Published
Jan 25, 2024
Exploitation Reported
Mar 07, 2026
CVSS
8.8 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
Juniper Networks
Junos OS

0 to < 20.4R3-S10

Affected
Juniper Networks
Junos OS

21.2 to < 21.2R3-S8

Affected
Juniper Networks
Junos OS

21.4 to < 21.4R3-S6

Affected
Juniper Networks
Junos OS

22.1 to < 22.1R3-S5

Affected
Juniper Networks
Junos OS

22.2 to < 22.2R3-S3

Affected
Juniper Networks
Junos OS

22.3 to < 22.3R3-S2

Affected
Juniper Networks
Junos OS

22.4 to < 22.4R3-S1

Affected
Juniper Networks
Junos OS

23.2 to < 23.2R2

Affected
Juniper Networks
Junos OS

23.4 to < 23.4R2

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.