CVE-2023-36851
KEVlarge1Unauthenticated Arbitrary File Upload/Download in Juniper SRX Series J-Web
CISA: Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
This is a missing-authentication flaw (CWE-306) in the J-Web web management interface of Juniper Networks Junos OS running on SRX Series firewalls. An unauthenticated, network-based attacker can send a crafted request to webauth_operation.php, which requires no authentication, and upload or download arbitrary files on the device. The result is limited loss of file system integrity and potential loss of confidentiality, and the file access may be chained with other vulnerabilities to increase impact. Any organization running an affected Junos OS release on an SRX Series device with J-Web enabled is affected, especially where that interface is reachable from untrusted networks. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2023-11-13 as one of five Juniper flaws and set a patch deadline of November 17, 2023.
What to do: Upgrade affected SRX Series devices to the fixed releases: 21.2R3-S8, 21.4R3-S6, 22.1R3-S5, 22.2R3-S3, 22.3R3-S2, 22.4R2-S2 or 22.4R3, or 23.2R1-S2 or 23.2R2 (or later). As an interim mitigation, disable J-Web or restrict it to trusted management networks and interfaces only. Review device logs for unauthenticated requests to webauth_operation.php as evidence of exploitation, and prioritize patching given the CISA KEV deadline of November 17, 2023.
| Juniper Junos OS on SRX Series | 21.2 versions prior to 21.2R3-S8; 21.4 versions prior to 21.4R3-S6; 22.1 versions prior to 22.1R3-S5; 22.2 versions prior to 22.2R3-S3; 22.3 versions prior to 2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload and download arbitrary files via J-Web, leading to a loss of integrity or confidentiality, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * 21.2 versions prior to 21.2R3-S8; * 21.4 versions prior to 21.4R3-S6; * 22.1 versions prior to 22.1R3-S5; * 22.2 versions prior to 22.2R3-S3; * 22.3 versions prior to 22.3R3-S2; * 22.4 versions prior to 22,4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S2, 23.2R2.
- Affected
- Juniper Junos OS
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- juniper
- Products
- junos
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N