EXPOSURES › CVE-2023-36845
CVE-2023-36845
HIGH ⌖ ON CISA KEV · EXPLOITEDJuniper Junos OS PHP External Variable Modification Vulnerability
An unauthenticated attacker can control an important environment variable in Juniper Junos OS EX and SRX Series, allowing code injection and execution. This vulnerability enables remote code execution and should be patched immediately to prevent exploitation.
Shame score — The vulnerability allows remote code execution, which is a severe security risk, and it was actively exploited before a patch was released.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code.
| PRODUCT | STATUS |
|---|---|
| Juniper Mist Juniper Networks |
In Process |