CVE-2023-36845

Confirmed PUBLISHED

Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable

Juniper Networks · Junos OS
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code. This issue affects Juniper Networks Junos OS on EX Series and SRX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3-S1; * 22.4 versions prior to 22.4R2-S1, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2.

cisa metasploit windows nuclei_scanner edge php
CVE Published
Aug 17, 2023
Exploitation Reported
Nov 13, 2023
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Juniper Networks
Junos OS

0 to < 20.4R3-S9

Affected
Juniper Networks
Junos OS

21.1 to < 21.1*

Affected
Juniper Networks
Junos OS

21.2 to < 21.2R3-S7

Affected
Juniper Networks
Junos OS

21.3 to < 21.3R3-S5

Affected
Juniper Networks
Junos OS

21.4 to < 21.4R3-S5

Affected
Juniper Networks
Junos OS

22.1 to < 22.1R3-S4

Affected
Juniper Networks
Junos OS

22.2 to < 22.2R3-S2

Affected
Juniper Networks
Junos OS

22.3 to < 22.3R2-S2, 22.3R3-S1

Affected
Juniper Networks
Junos OS

22.4 to < 22.4R2-S1, 22.4R3

Affected
Juniper Networks
Junos OS

23,2 to < 23.2R1-S1, 23.2R2

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.