ZeroHour

CVE-2023-36847

KEVlarge1

Unauthenticated Arbitrary File Upload in Juniper Junos OS EX Series J-Web

CISA: Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability

CVSS 3.1
5.3 medium
EPSS
86%p100
Published
()
KEV added
AI analysis

CVE-2023-36847 is a missing-authentication flaw (CWE-306) in the J-Web web-management interface of Juniper Networks Junos OS running on EX Series switches. An unauthenticated, network-based attacker can send a crafted request to installAppPackage.php that requires no login and upload arbitrary files to the device. The direct impact is limited to loss of file system integrity, but the file-write primitive can be chained with other recently disclosed J-Web flaws to achieve full unauthenticated remote code execution. Any EX Series switch on an affected Junos release with J-Web enabled and reachable is exposed, and public scans tied to this disclosure wave found nearly 12,000 internet-exposed Juniper devices vulnerable. The flaw is confirmed exploited in the wild: CISA added it to the KEV catalog on 2023-11-13 with a mitigation deadline of November 17, 2023, and EPSS assigns it an ~86% probability of exploitation within 30 days.

What to do: Upgrade EX Series switches to Junos OS 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S4, 22.1R3-S3, 22.2R3-S1, 22.3R2-S2 or 22.3R3, or 22.4R2-S1 or 22.4R3 (or later); 21.1 has no listed fix, so move to a fixed later release. Until patched, restrict or disable J-Web and limit web management to trusted management networks, per CISA's required action ahead of the November 17, 2023 KEV deadline. Check whether J-Web is internet-facing and review device logs for unauthenticated requests to installAppPackage.php.

Affected
Juniper Networks Junos OS on EX Series switchesAll versions prior to 20.4R3-S8; 21.1 versions 21.1R1 and later (no fixed 21.1 build listed); 21.2 versions prior to 21.2R3-S6; 21.3 versions prior to 21.3R3-S5
Estimated exposure
largetens of thousands of exposed devices (public scans tied to this disclosure found ≈12,000 vulnerable Juniper firewalls; internet-reachable EX Series J-Web is… — Public internet-scan reporting around this vulnerability wave identified nearly 12,000 vulnerable Juniper firewalls, and EX Series switches with J-Web exposed to the internet are plausibly on a similar order of magnitude.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S8; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S4; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S1; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3.

CISA Known Exploited Vulnerability
Affected
Juniper Junos OS
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
juniper
Products
junos
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news