Junglewise Threat Intelligence

CVE-2023-36847: Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability

CVE-2023-36847 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2023-11-13

Technologies: Juniper Junos OS. Vendors: Juniper, Juniper Networks.

Executive brief

A missing authentication vulnerability in the installAppPackage.php component of Juniper Junos OS on EX Series switches allows unauthenticated remote attackers to upload arbitrary files via J-Web. This can lead to a loss of file system integrity and may be used as part of a vulnerability chain.

Affected products

  • Juniper Networks Junos OS EX Series All versions prior to 20.4R3-S8; 21.1 versions 21.1R1 and later; 21.2 versions prior to 21.2R3-S6; 21.3 versions prior to 21.3R3-S5; 21.4 versions prior to 21.4R3-S4; 22.1 versions prior to 22.1R3-S3; 22.2 versions prior to 22.2R3-S1; 22.3 versions prior to 22.3R2-S2, 22.3R3; 22.4 versions prior to 22.4R2-S1, 22.4R3.

Timeline

  • 2023-11-13: disclosed
  • 2023-11-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-11-13: exploited

Related threats