Skip to content
COOEY

EXPOSURES › CVE-2023-36845

CVE-2023-36845

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-11-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-36845 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Juniper Junos OS PHP External Variable Modification Vulnerability

An unauthenticated attacker can control an important environment variable in Juniper Junos OS EX and SRX Series, allowing code injection and execution. This vulnerability enables remote code execution and should be patched immediately to prevent exploitation.

Shame score — The vulnerability allows remote code execution, which is a severe security risk, and it was actively exploited before a patch was released.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Juniper Mist
Juniper Networks
In Process