Juniper Junos SRX Series UAC Enforcer HTTP Remote Code Execution (JSA10574)
Critical Nessus Plugin ID 68907
SynopsisThe remote device is missing a vendor-supplied security patch.
DescriptionAccording to its self-reported version number, the remote Junos device has a remote code execution vulnerability. Sending a specially crafted HTTP request to an SRX series device can result in arbitrary code execution. A remote, unauthenticated attacker could exploit this to execute arbitrary code.
SRX series devices are only affected when configured as a Unified Access Control (UAC) enforcer in a UAC network with Captive Portal enabled.
SolutionApply the relevant Junos upgrade referenced in Juniper advisory JSA10574.