ZeroHour

CVE-2023-36845

KEV PoC ×2large

Unauthenticated RCE in Juniper J-Web on EX and SRX Series

CISA: Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability

CVSS 3.1
9.8 critical
EPSS
95%p100
Published
()
KEV added
AI analysis

A PHP external variable modification flaw (CVE-2023-36845) in the J-Web web management interface of Juniper Networks Junos OS on EX Series switches and SRX Series firewalls allows an unauthenticated, network-based attacker to remotely execute code. By sending a crafted request that sets the PHPRC variable, the attacker modifies the PHP execution environment to inject and execute code, gaining full control of the device with high impact on confidentiality, integrity, and availability (CVSS 9.8). All EX and SRX devices running affected Junos OS versions — from all builds prior to 20.4R3-S9 through the 23.2 line — are affected where the J-Web interface is reachable. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on November 13, 2023, public PoC exploit code is available, and public scans found nearly 12,000 vulnerable Juniper firewalls exposed to the internet, prompting a CISA patch deadline of November 17.

What to do: Upgrade affected EX/SRX devices to a fixed Junos OS release: 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S2, 22.3R2-S2 or 22.3R3-S1, 22.4R2-S1 or 22.4R3, or 23.2R1-S1 or 23.2R2 (or later). As an interim mitigation, disable J-Web or restrict access to trusted management networks, and review web interface logs for crafted requests setting PHPRC. Federal defenders should patch by CISA's November 17 KEV deadline.

Affected
Juniper Networks Junos OS (J-Web on EX Series and SRX Series)All versions prior to 20.4R3-S9; all 21.1 versions (21.1R1 and later); 21.2 prior to 21.2R3-S7; 21.3 prior to 21.3R3-S5; 21.4 prior to 21.4R3-S5; 22.1 prior to
Estimated exposure
large≈12,000 internet-exposed Juniper firewalls (public vulnerability scans); total installed base likely higher — Public internet scans conducted after the PoC release found nearly 12,000 vulnerable Juniper SRX/EX devices exposed online, and only deployments with J-Web reachable are at risk, so the broader installed base is plausibly larger but…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code. This issue affects Juniper Networks Junos OS on EX Series and SRX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3-S1; * 22.4 versions prior to 22.4R2-S1, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2.

CISA Known Exploited Vulnerability
Affected
Juniper Junos OS
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
juniper
Products
junos
Weakness
CWE-473
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news