Junglewise Threat Intelligence

CVE-2023-36851: Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

CVE-2023-36851 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2023-11-13

Technologies: Juniper Junos OS. Vendors: Juniper, Juniper Networks.

Executive brief

A missing authentication vulnerability in the webauth_operation.php component of Juniper Junos OS on SRX Series allows unauthenticated network-based attackers to upload and download arbitrary files via J-Web. This can lead to a loss of file system integrity and confidentiality, potentially serving as a vector for chaining further attacks.

Affected products

  • Juniper Networks Junos OS SRX Series 21.2 versions prior to 21.2R3-S8; 21.4 versions prior to 21.4R3-S6; 22.1 versions prior to 22.1R3-S5; 22.2 versions prior to 22.2R3-S3; 22.3 versions prior to 22.3R3-S2; 22.4 versions prior to 22,4R2-S2, 22.4R3; 23.2 versions prior to 23.2R1-S2, 23.2R2.

Timeline

  • 2023-11-13: disclosed
  • 2023-11-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-11-13: exploited: Reported as exploited in the wild per CISA KEV and advisory metadata.

Related threats