ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Sets a Deadline - Patch Juniper Junos OS Flaws Before November 17

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-36845
+3 in the same advisory: …36846 …36844 …36847
Unauthenticated RCE in Juniper J-Web on EX and SRX Series

A PHP external variable modification flaw (CVE-2023-36845) in the J-Web web management interface of Juniper Networks Junos OS on EX Series switches and SRX Series firewalls allows an unauthenticated, network-based attacker to remotely execute code. By sending a crafted request that sets the PHPRC variable, the attacker modifies the PHP execution environment to inject and execute code, gaining full control of the device with high impact on confidentiality, integrity, and availability (CVSS 9.8). All EX and SRX devices running affected Junos OS versions — from all builds prior to 20.4R3-S9 through the 23.2 line — are affected where the J-Web interface is reachable. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on November 13, 2023, public PoC exploit code is available, and public scans found nearly 12,000 vulnerable Juniper firewalls exposed to the internet, prompting a CISA patch deadline of November 17.

Do: Upgrade affected EX/SRX devices to a fixed Junos OS release: 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S2, 22.3R2-S2 or 22.3R3-S1, 22.4R2-S1 or 22.4R3, or 23.2R1-S1 or 23.2R2 (or later). As an interim mitigation, disable J-Web or restrict access to trusted management networks, and review web interface logs for crafted requests setting PHPRC. Federal defenders should patch by CISA's November 17 KEV deadline.

9.8
group max
95% KEV PoC ×2
  • Juniper Networks Junos OS (J-Web on EX Series and SRX Series) All versions prior to 20.4R3-S9; all 21.1 versions (21.1R1 and later); 21.2 prior to 21.2R3-S7; 21.3 prior to 21.3R3-S5; 21.4 prior to 21.4R3-S5; 22.1 prior to
large≈12,000 internet-exposed Juniper firewalls (public vulnerability scans); total installed base likely higher
CVE-2023-36851
Unauthenticated Arbitrary File Upload/Download in Juniper SRX Series J-Web

This is a missing-authentication flaw (CWE-306) in the J-Web web management interface of Juniper Networks Junos OS running on SRX Series firewalls. An unauthenticated, network-based attacker can send a crafted request to webauth_operation.php, which requires no authentication, and upload or download arbitrary files on the device. The result is limited loss of file system integrity and potential loss of confidentiality, and the file access may be chained with other vulnerabilities to increase impact. Any organization running an affected Junos OS release on an SRX Series device with J-Web enabled is affected, especially where that interface is reachable from untrusted networks. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2023-11-13 as one of five Juniper flaws and set a patch deadline of November 17, 2023.

Do: Upgrade affected SRX Series devices to the fixed releases: 21.2R3-S8, 21.4R3-S6, 22.1R3-S5, 22.2R3-S3, 22.3R3-S2, 22.4R2-S2 or 22.4R3, or 23.2R1-S2 or 23.2R2 (or later). As an interim mitigation, disable J-Web or restrict it to trusted management networks and interfaces only. Review device logs for unauthenticated requests to webauth_operation.php as evidence of exploitation, and prioritize patching given the CISA KEV deadline of November 17, 2023.

5.31% KEV
  • Juniper Junos OS on SRX Series 21.2 versions prior to 21.2R3-S8; 21.4 versions prior to 21.4R3-S6; 22.1 versions prior to 22.1R3-S5; 22.2 versions prior to 22.2R3-S3; 22.3 versions prior to 2
largetens of thousands of internet-exposed SRX firewalls with J-Web enabled (a subset of a very large installed base)
Full article421 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 14, 2023Cyber Attack / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given a November 17, 2023, deadline for federal agencies and organizations to apply mitigations to secure against a number of security flaws in Juniper Junos OS that came to light in August.

The agency on Monday added five vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation -

  • CVE-2023-36844 (CVSS score: 5.3) - Juniper Junos OS EX Series PHP External Variable Modification Vulnerability
  • CVE-2023-36845 (CVSS score: 5.3) - Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability
  • CVE-2023-36846 (CVSS score: 5.3) - Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
  • CVE-2023-36847 (CVSS score: 5.3) - Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability
  • CVE-2023-36851 (CVSS score: 5.3) - Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

The vulnerabilities, per Juniper, could be fashioned into an exploit chain to achieve remote code execution on unpatched devices. Also added to the list is CVE-2023-36851, which has been described as a variant of the SRX upload flaw.

Juniper, in an update to its advisory on November 8, 2023, said it's "now aware of successful exploitation of these vulnerabilities," recommending that customers update to the latest versions with immediate effect.

The details surrounding the nature of the exploitation are currently unknown.

In a separate alert, CISA has also warned that the Royal ransomware gang may rebrand as BlackSuit owing to the fact that the latter shares a "number of identified coding characteristics similar to Royal."

The development comes as Cyfirma disclosed that exploits for critical vulnerabilities are being offered for sale on darknet forums and Telegram channels.

"These vulnerabilities encompass elevation of privilege, authentication bypass, SQL injection, and remote code execution, posing significant security risks," the cybersecurity firm said, adding, "ransomware groups are actively searching for zero-day vulnerabilities in underground forums to compromise a large number of victims."

It also follows revelations from Huntress that threat actors are targeting multiple healthcare organizations by abusing the widely-used ScreenConnect remote access tool used by Transaction Data Systems, a pharmacy management software provider, for initial access.

"The threat actor proceeded to take several steps, including installing additional remote access tools such as ScreenConnect or AnyDesk instances, to ensure persistent access to the environments," Huntress noted.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/11/cisa-sets-deadline-patch-juniper-junos.html