An Incorrect Authorization vulnerability in the web...
        
  Moderate severity
        
          Unreviewed
      
        Published
          Jul 11, 2025 
          to the GitHub Advisory Database
          •
          Updated Jul 11, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Jul 11, 2025 
    
  
        Published to the GitHub Advisory Database
      Jul 11, 2025 
    
  
        Last updated
      Jul 11, 2025 
    
  
An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to reach the
Juniper Web Device Manager
(J-Web).
When Juniper Secure connect (JSC) is enabled on specific interfaces, or multiple interfaces are configured for J-Web, the J-Web UI is reachable over more than the intended interfaces.
This issue affects Junos OS:
References