CVE-2020-1631 — Juniper Junos OS Path Traversal Vulnerability
2022-03-25 • CISA Known Exploited Vulnerability
[event] A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | Juniper |
| Product | Junos OS |
| CWE | CWE-22, CWE-73 |
| CVE ID | CVE-2020-1631 |
| Date Added | 2022-03-25 |
| Due Date | 2022-04-15 |
| Ransomware Campaign | Unknown |
> MITIGATION
Apply updates per vendor instructions.
Due Date: 2022-04-15