Juniper Networks released out-of-band updates to fix high
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-36846 | Unauthenticated File Upload in Juniper Junos OS SRX J-Web Chainable to RCE CVE-2023-36846 is a Missing Authentication for Critical Function flaw (CWE-306) in the J-Web web-management interface of Juniper Networks Junos OS running on SRX Series firewalls: a specific unauthenticated request to user.php allows an attacker to upload arbitrary files. Successful uploads compromise the integrity of part of the file system and can be chained with other recently disclosed Juniper J-Web vulnerabilities to achieve full unauthenticated remote code execution. Any SRX Series device running an affected Junos OS release with J-Web reachable over the network is affected; Juniper issued out-of-band fixes and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-11-13 with a federal patch deadline of November 17. Exploitation is confirmed in the wild, as threat actors began attacking the Juniper J-Web flaws shortly after public PoC code was released, and EPSS assigns a ~95% probability of exploitation within 30 days. Internet-wide scans identified nearly 12,000 vulnerable Juniper firewalls exposed, indicating exposure concentrated on internet-facing edge devices. Do: Upgrade affected SRX Series devices to a fixed Junos OS release: 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S5, 22.1R3-S3, 22.2R3-S2, 22.3R2-S2 or 22.3R3, or 22.4R2-S1 or 22.4R3 (devices on 21.1 must move to a later supported release). Until patching, disable J-Web or restrict it to trusted management networks, and verify devices for compromise since in-the-wild exploitation and CISA KEV listing (federal deadline November 17) are already in effect. | 5.3 | 95% | KEV |
| large~12,000 internet-exposed Juniper SRX firewalls (public scan of the related J-Web RCE); total SRX install base likely larger | |
| CVE-2023-3685 | A vulnerability was found in Nesote Inout Search Engine AI Edition 1.1. A vulnerability was found in Nesote Inout Search Engine AI Edition 1.1. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-234231. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2023-36851 | Unauthenticated Arbitrary File Upload/Download in Juniper SRX Series J-Web This is a missing-authentication flaw (CWE-306) in the J-Web web management interface of Juniper Networks Junos OS running on SRX Series firewalls. An unauthenticated, network-based attacker can send a crafted request to webauth_operation.php, which requires no authentication, and upload or download arbitrary files on the device. The result is limited loss of file system integrity and potential loss of confidentiality, and the file access may be chained with other vulnerabilities to increase impact. Any organization running an affected Junos OS release on an SRX Series device with J-Web enabled is affected, especially where that interface is reachable from untrusted networks. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2023-11-13 as one of five Juniper flaws and set a patch deadline of November 17, 2023. Do: Upgrade affected SRX Series devices to the fixed releases: 21.2R3-S8, 21.4R3-S6, 22.1R3-S5, 22.2R3-S3, 22.3R3-S2, 22.4R2-S2 or 22.4R3, or 23.2R1-S2 or 23.2R2 (or later). As an interim mitigation, disable J-Web or restrict it to trusted management networks and interfaces only. Review device logs for unauthenticated requests to webauth_operation.php as evidence of exploitation, and prioritize patching given the CISA KEV deadline of November 17, 2023. | 5.3 | 1% | KEV |
| largetens of thousands of internet-exposed SRX firewalls with J-Web enabled (a subset of a very large installed base) | |
| CVE-2024-21619 +1 in the same advisory: …21620 | A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access sensitive system information. When a user logs in, a temporary file which contains the configuration of the device (as visible to that user) is created in the /cache folder. An unauthenticated attacker can then attempt to access such a file by sending a specific request to the device trying to guess the name of such a file. Successful exploitation will reveal configuration information. This issue affects Juniper Networks Junos OS on SRX Series and EX Series: * All versions earlier than 20.4R3-S9; * 21.2 versions earlier than 21.2R3-S7; * 21.3 versions earlier than 21.3R3-S5; * 21.4 versions earlier than 21.4R3-S6; * 22.1 versions earlier than 22.1R3-S5; * 22.2 versions earlier than 22.2R3-S3; * 22.3 versions earlier than 22.3R3-S2; * 22.4 versions earlier than 22.4R3; * 23.2 versions earlier than 23.2R1-S2, 23.2R2. NVD description · AI analysis pending | 7.5 group max | <1% |
| — |
Full article377 words · extracted from securityaffairs.com · click to collapse

Juniper Networks released out-of-band updates to fix high-severity flaws in SRX Series and EX Series that can allow attackers to take over unpatched systems.
Juniper Networks has released out-of-band updates to address two high-severity flaws, tracked as CVE-2024-21619 and CVE-2024-21620, in SRX Series and EX Series that could be exploited by a threat actor to take control of susceptible systems.
The flaw CVE-2024-21619 (CVSS score: 5.3) is a Missing Authentication for Critical Function vulnerability. An unauthenticated, network-based attacker can chain this issue with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series to access sensitive system information.
“When a user logs in, a temporary file which contains the configuration of the device (as visible to that user) is created in the /cache folder.” reads the advisory. “An unauthenticated attacker can then attempt to access such a file by sending a specific request to the device trying to guess the name of such a file. Successful exploitation will reveal configuration information.”
The flaw CVE-2024-21620 (CVSS score: 8.8) is an Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series. An attacker can trigger the flaw to craft a URL that when visited by another user enables the attacker to execute commands with the target’s permissions, including an administrator. A specific invocation of the emit_debug_note method in webauth_operation.php will echo back the data it receives.
The vendor also addressed two other vulnerabilities respectively tracked as CVE-2023-36846 and CVE-2023-36851:
- CVE-2023-36846 (CVSS score: 5.3) – A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity.
- CVE-2023-36851 (CVSS score: 5.3) – A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity.
The vulnerability was reported by cybersecurity firm watchtowr. As a workaround the company recommends disabling J-Web, or limiting access to only trusted hosts
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Juniper Networks)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/158341/security/juniper-networks-flaws-srx-series-ex-series.html