CVE-2023-36851

Confirmed PUBLISHED

Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files

Juniper Networks · Junos OS
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
5.3 Medium

At a Glance

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload and download arbitrary files via J-Web, leading to a loss of integrity or confidentiality, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * 21.2 versions prior to 21.2R3-S8; * 21.4 versions prior to 21.4R3-S6; * 22.1 versions prior to 22.1R3-S5; * 22.2 versions prior to 22.2R3-S3; * 22.3 versions prior to 22.3R3-S2; * 22.4 versions prior to 22,4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S2, 23.2R2.

edge php nessus_scanner cisa
CVE Published
Sep 26, 2023
Exploitation Reported
Nov 13, 2023
CVSS
5.3 Medium
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Juniper Networks
Junos OS

21.2 to < 21.2R3-S8

Affected
Juniper Networks
Junos OS

21.4 to < 21.4R3-S6

Affected
Juniper Networks
Junos OS

22.1 to < 22.1R3-S5

Affected
Juniper Networks
Junos OS

22.2 to < 22.2R3-S3

Affected
Juniper Networks
Junos OS

22.3 to < 22.3R3-S2

Affected
Juniper Networks
Junos OS

22.4 to < 22.4R2-S2, 22.4R3

Affected
Juniper Networks
Junos OS

23.2 to < 23.2R1-S2, 23.2R2

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.