ZeroHour

CVE-2023-36846

KEVlarge

Unauthenticated File Upload in Juniper Junos OS SRX J-Web Chainable to RCE

CISA: Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

CVSS 3.1
5.3 medium
EPSS
95%p100
Published
()
KEV added
AI analysis

CVE-2023-36846 is a Missing Authentication for Critical Function flaw (CWE-306) in the J-Web web-management interface of Juniper Networks Junos OS running on SRX Series firewalls: a specific unauthenticated request to user.php allows an attacker to upload arbitrary files. Successful uploads compromise the integrity of part of the file system and can be chained with other recently disclosed Juniper J-Web vulnerabilities to achieve full unauthenticated remote code execution. Any SRX Series device running an affected Junos OS release with J-Web reachable over the network is affected; Juniper issued out-of-band fixes and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-11-13 with a federal patch deadline of November 17. Exploitation is confirmed in the wild, as threat actors began attacking the Juniper J-Web flaws shortly after public PoC code was released, and EPSS assigns a ~95% probability of exploitation within 30 days. Internet-wide scans identified nearly 12,000 vulnerable Juniper firewalls exposed, indicating exposure concentrated on internet-facing edge devices.

What to do: Upgrade affected SRX Series devices to a fixed Junos OS release: 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S5, 22.1R3-S3, 22.2R3-S2, 22.3R2-S2 or 22.3R3, or 22.4R2-S1 or 22.4R3 (devices on 21.1 must move to a later supported release). Until patching, disable J-Web or restrict it to trusted management networks, and verify devices for compromise since in-the-wild exploitation and CISA KEV listing (federal deadline November 17) are already in effect.

Affected
Juniper Networks Junos OS on SRX Series (J-Web interface)All versions prior to 20.4R3-S8; 21.1 versions 21.1R1 and later (no fixed 21.1 build listed); 21.2 versions prior to 21.2R3-S6; 21.3 versions prior to 21.3R3-S5
Estimated exposure
large~12,000 internet-exposed Juniper SRX firewalls (public scan of the related J-Web RCE); total SRX install base likely larger — Public internet-wide scans reported nearly 12,000 Juniper firewalls vulnerable to the companion no-auth RCE in the same J-Web interface, and only devices with J-Web reachable are exploitable, though the overall SRX installed base is larger.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * All versions prior to 20.4R3-S8; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3.

CISA Known Exploited Vulnerability
Affected
Juniper Junos OS
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
juniper
Products
junos
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news