Executive brief
A PHP External Variable Modification vulnerability in the J-Web component of Juniper Networks Junos OS on EX Series switches allows unauthenticated network-based attackers to control critical environment variables. By sending crafted requests, an attacker can modify PHP environment variables, potentially leading to a partial loss of integrity or enabling the chaining of further vulnerabilities.
Affected products
- Juniper Networks Junos OS EX Series All versions prior to 20.4R3-S9; 21.1 versions 21.1R1 and later; 21.2 versions prior to 21.2R3-S7; 21.3 versions prior to 21.3R3-S5; 21.4 versions prior to 21.4R3-S5; 22.1 versions prior to 22.1R3-S4; 22.2 versions prior to 22.2R3-S2; 22.3 versions prior to 22.3R3-S1; 22.4 versions prior to 22.4R2-S2, 22.4R3; 23.2 versions prior to 23.2R1-S1, 23.2R2.
Timeline
- 2023-11-13: disclosed: Published date and date added to CISA KEV catalog.
- 2023-11-13: kev added
- 2023-11-17: other: CISA due date for mitigation.