Skip to content
COOEY

EXPOSURES › CVE-2023-36851

CVE-2023-36851

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-11-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-36851 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Juniper Junos OS SRX Series missing authentication for critical function allows file upload via J-Web.

An unauthenticated attacker can upload arbitrary files via J-Web on Juniper Junos OS SRX Series, leading to potential file system integrity loss. This vulnerability allows attackers to exploit other vulnerabilities in the system. DIB organizations should ensure they are using patched versions of Junos OS SRX Series to mitigate this risk.

Shame score — The vulnerability allows an attacker to upload arbitrary files, which can lead to significant data loss and potential exploitation of other vulnerabilities.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Juniper Mist
Juniper Networks
In Process