Junglewise Threat Intelligence

CVE-2023-36846: Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

CVE-2023-36846 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2023-11-13

Technologies: Juniper Junos OS. Vendors: Juniper, Juniper Networks.

Executive brief

A missing authentication vulnerability in the J-Web component of Juniper Junos OS on SRX Series devices allows unauthenticated attackers to upload arbitrary files via a specific request to user.php. This can lead to a loss of file system integrity and may be used as a primitive to chain with other vulnerabilities.

Affected products

  • Juniper Networks Junos OS SRX Series All versions prior to 20.4R3-S8; 21.1 versions 21.1R1 and later; 21.2 versions prior to 21.2R3-S6; 21.3 versions prior to 21.3R3-S5; 21.4 versions prior to 21.4R3-S5; 22.1 versions prior to 22.1R3-S3; 22.2 versions prior to 22.2R3-S2; 22.3 versions prior to 22.3R2-S2, 22.3R3; 22.4 versions prior to 22.4R2-S1, 22.4R3.

Timeline

  • 2023-11-13: disclosed
  • 2023-11-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-11-13: advisory: NVD publication date

Related threats