ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

New Juniper Junos OS Flaws Expose Devices to Remote Attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-36845
+3 in the same advisory: …36846 …36844 …36847
Unauthenticated RCE in Juniper J-Web on EX and SRX Series

A PHP external variable modification flaw (CVE-2023-36845) in the J-Web web management interface of Juniper Networks Junos OS on EX Series switches and SRX Series firewalls allows an unauthenticated, network-based attacker to remotely execute code. By sending a crafted request that sets the PHPRC variable, the attacker modifies the PHP execution environment to inject and execute code, gaining full control of the device with high impact on confidentiality, integrity, and availability (CVSS 9.8). All EX and SRX devices running affected Junos OS versions — from all builds prior to 20.4R3-S9 through the 23.2 line — are affected where the J-Web interface is reachable. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on November 13, 2023, public PoC exploit code is available, and public scans found nearly 12,000 vulnerable Juniper firewalls exposed to the internet, prompting a CISA patch deadline of November 17.

Do: Upgrade affected EX/SRX devices to a fixed Junos OS release: 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S2, 22.3R2-S2 or 22.3R3-S1, 22.4R2-S1 or 22.4R3, or 23.2R1-S1 or 23.2R2 (or later). As an interim mitigation, disable J-Web or restrict access to trusted management networks, and review web interface logs for crafted requests setting PHPRC. Federal defenders should patch by CISA's November 17 KEV deadline.

9.8
group max
95% KEV PoC ×2
  • Juniper Networks Junos OS (J-Web on EX Series and SRX Series) All versions prior to 20.4R3-S9; all 21.1 versions (21.1R1 and later); 21.2 prior to 21.2R3-S7; 21.3 prior to 21.3R3-S5; 21.4 prior to 21.4R3-S5; 22.1 prior to
large≈12,000 internet-exposed Juniper firewalls (public vulnerability scans); total installed base likely higher
Full article434 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 19, 2023Network Security / Vulnerability

Networking hardware company Juniper Networks has released an "out-of-cycle" security update to address multiple flaws in the J-Web component of Junos OS that could be combined to achieve remote code execution on susceptible installations.

The four vulnerabilities have a cumulative CVSS rating of 9.8, making them Critical in severity. They affect all versions of Junos OS on SRX and EX Series.

"By chaining exploitation of these vulnerabilities, an unauthenticated, network-based attacker may be able to remotely execute code on the devices," the company said in an advisory released on August 17, 2023.

The J-Web interface allows users to configure, manage, and monitor Junos OS devices. A brief description of the flaws is as follows -

  • CVE-2023-36844 and CVE-2023-36845 (CVSS scores: 5.3) - Two PHP external variable modification vulnerabilities in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain, important environments variables.
  • CVE-2023-36846 and CVE-2023-36847 (CVSS scores: 5.3) - Two missing authentications for critical function vulnerabilities in Juniper Networks Junos OS on EX Series and SRX Series allow an unauthenticated, network-based attacker to cause limited impact to the file system integrity.

A threat actor could send a specially crafted request to modify certain PHP environment variables or upload arbitrary files via J-Web sans any authentication to successfully exploit the aforementioned issues.

The vulnerabilities have been addressed in the below versions -

  • EX Series - Junos OS versions 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S4, 22.1R3-S3, 22.2R3-S1, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3, and 23.2R1
  • SRX Series - Junos OS versions 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S5, 22.1R3-S3, 22.2R3-S2, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3, and 23.2R1

Users are recommended to apply the necessary fixes to mitigate potential remote code execution threats. As a workaround, Juniper Networks is suggesting that users either disable J-Web or limit access to only trusted hosts.

PoC Exploit Released

Proof-of-concept (PoC) exploit code has been released for multiple security flaws in Juniper SRX firewalls that, when chained, can allow unauthenticated attackers to gain remote code execution on unpatched devices.

The PoC, published by watchTowr, combines CVE-2023-36846 and CVE-2023-36845 to upload a PHP file containing malicious shellcode and achieve code execution by injecting the PHPRC environment variable to point to a configuration file in order to load the booby-trapped PHP script.

"This is an interesting bug chain, utilizing two bugs that would be near-useless in isolation and combining them for a 'world ending' unauthenticated RCE," the company said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/08/new-juniper-junos-os-flaws-expose.html