CRITICAL

CVE-2023-36845

Juniper Junos 2023-08-17 CVSS v3.1
CVSS
9.8
KEV

Description

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series

and SRX Series

allows an unauthenticated, network-based attacker to remotely execute code.

Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code.


This issue affects Juniper Networks Junos OS on EX Series


and


SRX Series:



* All versions prior to

20.4R3-S9;
* 21.1 versions 21.1R1 and later;
* 21.2 versions prior to 21.2R3-S7;
* 21.3 versions prior to 21.3R3-S5;
* 21.4 versions prior to 21.4R3-S5;
* 22.1 versions

prior to

22.1R3-S4;
* 22.2 versions

prior to

22.2R3-S2;
* 22.3 versions

prior to

22.3R2-S2, 22.3R3-S1;
* 22.4 versions

prior to

22.4R2-S1, 22.4R3;
* 23.2 versions prior to 23.2R1-S1, 23.2R2.

Summary dbcve.org

A PHP External Variable Modification vulnerability in J-Web allows unauthenticated remote attackers to set the PHPRC environment variable via crafted HTTP requests, modifying the PHP execution environment and enabling arbitrary code execution on Juniper Junos OS EX and SRX Series devices.

Mitigation

Upgrade Junos OS to a patched version (20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S2, 22.3R3-S1, 22.4R2-S1, 23.2R1-S1, or later), or restrict network access to J-Web interface as a temporary workaround.

Proof of Concept

Weakness (CWE)

CWE-473

EPSS Score

95.07%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE