CVE-2023-36847

Confirmed PUBLISHED

Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files

Juniper Networks · Junos OS
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
5.3 Medium

At a Glance

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S8; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S4; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S1; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3.

nessus_scanner edge cisa php
CVE Published
Aug 17, 2023
Exploitation Reported
Nov 13, 2023
CVSS
5.3 Medium
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Juniper Networks
Junos OS

0 to < 20.4R3-S8

Affected
Juniper Networks
Junos OS

21.1 to < 21.1*

Affected
Juniper Networks
Junos OS

21.2 to < 21.2R3-S6

Affected
Juniper Networks
Junos OS

21.3 to < 21.3R3-S5

Affected
Juniper Networks
Junos OS

21.4 to < 21.4R3-S4

Affected
Juniper Networks
Junos OS

22.1 to < 22.1R3-S3

Affected
Juniper Networks
Junos OS

22.2 to < 22.2R3-S1

Affected
Juniper Networks
Junos OS

22.3 to < 22.3R2-S2, 22.3R3

Affected
Juniper Networks
Junos OS

22.4 to < 22.4R2-S1, 22.4R3

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.