ZeroHour

CVE-2023-36844

KEV PoC large1

Unauthenticated PHP Environment Variable Flaw in Juniper Junos OS EX Series J-Web

CISA: Juniper Junos OS EX Series PHP External Variable Modification Vulnerability

CVSS 3.1
5.3 medium
EPSS
90%p100
Published
()
KEV added
AI analysis

CVE-2023-36844 is a PHP external variable modification flaw (CWE-473) in the J-Web web-management interface of Juniper Networks Junos OS on EX Series switches. An unauthenticated, network-based attacker can send a crafted request to J-Web to modify important PHP environment variables, causing a partial loss of integrity that, when chained with other recently disclosed Junos J-Web flaws, enables full unauthenticated remote code execution as demonstrated in a public proof-of-concept. Nearly all current Junos releases on EX Series are affected, spanning all versions prior to 20.4R3-S9 through 23.2 versions prior to 23.2R1-S1 and 23.2R2. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on November 13, 2023 with a remediation deadline of November 17, 2023, and threat actors began exploiting the Juniper flaw family shortly after PoC code was released. Public internet scans have already identified nearly 12,000 vulnerable Juniper devices, underscoring broad exposure of internet-facing J-Web interfaces.

What to do: Upgrade EX Series devices to a fixed Junos release: 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S2, 22.3R3-S1, 22.4R2-S2 or 22.4R3, or 23.2R1-S1 or 23.2R2; the 21.1 train (21.1R1 and later) has no fixed 21.1 version listed, so move to a fixed later release. As an interim mitigation, disable J-Web or restrict it to trusted management networks, and inventory internet-facing Junos devices for compromise; CISA's KEV required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

Affected
Juniper Networks Junos OS on EX Series (J-Web web-management interface)All versions prior to 20.4R3-S9; 21.1 versions 21.1R1 and later; 21.2 versions prior to 21.2R3-S7; 21.3 versions prior to 21.3R3-S5; 21.4 versions prior to 21.4
Estimated exposure
large≈12,000 internet-exposed vulnerable Juniper devices identified in public scans (EX switch exposure additional and unquantified) — Public internet-wide scans reported nearly 12,000 Juniper firewalls vulnerable to the related no-auth RCE chain shortly after disclosure, and EX Series switches with J-Web enabled add an unknown but likely comparable share of exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R3-S1; * 22.4 versions prior to 22.4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2.

CISA Known Exploited Vulnerability
Affected
Juniper Junos OS
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
juniper
Products
junos
Weakness
CWE-473
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news