MEDIUM

CVE-2023-36846

Juniper Junos 2023-08-17 CVSS v3.1
CVSS
5.3
KEV

Description

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity.



With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of

integrity

for a certain 

part of the file system, which may allow chaining to other vulnerabilities.


This issue affects Juniper Networks Junos OS on SRX Series:



* All versions prior to 20.4R3-S8;
* 21.1 versions 21.1R1 and later;
* 21.2 versions prior to 21.2R3-S6;
* 21.3 versions

prior to

21.3R3-S5;
* 21.4 versions

prior to

21.4R3-S5;
* 22.1 versions

prior to

22.1R3-S3;
* 22.2 versions

prior to

22.2R3-S2;
* 22.3 versions

prior to

22.3R2-S2, 22.3R3;
* 22.4 versions

prior to

22.4R2-S1, 22.4R3.

Summary dbcve.org

A missing authentication vulnerability in J-Web's user.php component allows unauthenticated attackers to upload arbitrary files to the SRX file system. This bypasses all authentication controls, enabling potential remote code execution when chained with other vulnerabilities.

Mitigation

Upgrade Junos OS to one of the fixed versions listed (20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S5, 22.1R3-S3, 22.2R3-S2, 22.3R2-S2/22.3R3, or 22.4R2-S1/22.4R3 depending on the branch).

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

93.47%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE