By using this site, you agree to the Privacy Policy and Terms of Use.
Accept

Tec Informer

Tech news, Tips, tutorials , health tips and job circular

  • Latest
  • Mobile
  • Gadgets
  • Internet
  • Virtual reality
  • Artificial intelligence
  • Computing
Search here
Notification Show More
Aa

Tec Informer

Tech news, Tips, tutorials , health tips and job circular

Aa
Search here
Follow US
2023 © TECINFORMER All Rights Reserved
Tec Informer > Tech News > Thousands of Juniper firewalls are open to serious attack -TECINFORMER
Tech News

Thousands of Juniper firewalls are open to serious attack -TECINFORMER

Tecinformer
Last updated: 2023/09/19 at 2:23 PM
Tecinformer
Share
2 Min Read
Cyberattack
SHARE

Contents
Exploiting known flawsMore from TechRadar Pro

A month after a patch was released, an overwhelming majority of Juniper’s SRX firewalls and EX Series switches remain vulnerable to a group of flaws which, when combined, can result in remote code execution, according to threat intelligence platform provider, VulnCheck.

In its findings, The Register reports, VulnCheck says that on August 17, Juniper announced finding, and patching, five separate vulnerabilities affecting all versions of Junos OS on SRX firewalls and EX Series switches. 

These vulnerabilities are now tracked as CVE-2023-36844, CVE-2023-36845, CVE-2023-36846, CVE-2023-36847, and CVE-2023-36851. While individually they carry a 5.3 severity rating, collectively they earned a 9.8 score and have been deemed critical. Some researchers say that by chaining these five, threat actors are able to achieve remote code execution, which could lead to a whole host of other issues, such as malware deployment. Other researchers believe that chaining just some will suffice.

Table of Contents

  • Exploiting known flaws
    • More from TechRadar Pro

Exploiting known flaws

Now, a month later, roughly four in five (79%) public-facing Juniper SRX firewalls and EX Series switches are yet to be patched up and remain vulnerable to these flaws. To make matters worse, more than ten days ago Juniper updated its security advisory to say it observed threat actors attempting to exploit these flaws. 

According to numerous research, hackers are more inclined towards abusing older, known flaws, rather than trying to discover their own zero-day vulnerabilities. That is because older flaws already have proof-of-concepts and are easily exploited, especially knowing that many firms aren’t that diligent when it comes to applying patches and upgrades.

To remain secure, businesses are advised to apply new fixes and patches as soon as they roll out or to have a solid patching schedule to adhere to. 

If you’re unsure whether or not your firewall is vulnerable to CVE-2023-36845, VulnCheck has released a free scanning tool which you can find on this link. 

More from TechRadar Pro

Read the full article here

Share This Article
Facebook Twitter Copy Link Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You Might Also Like

Google iPager ad screenshot
Tech News

Google’s iPager ad again blames Apple for green bubbles and other messaging woes -TECINFORMER

September 23, 2023
Here's why AI expert Meredith Whittaker is worried about 'artificial intelligence'
Tech News

Here's why AI expert Meredith Whittaker is worried about 'artificial intelligence' -TECINFORMER

September 23, 2023
iPhone 15 review images
Tech News

Switching to an iPhone 15 from an older iPhone? Do this first and thank us later -TECINFORMER

September 23, 2023
apple homepod
Tech News

Apple HomePod finally gets hands-free Spotify thanks to this iOS 17 workaround -TECINFORMER

September 22, 2023
Follow US
2023 © TECINFORMER All Rights Reserved
  • Disclaimer
  • Terms
  • Contact Us
  • About us
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?