CVE-2023-36844: Juniper Junos OS EX Series PHP External Variable Modification Vulnerability
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables.
Using a crafted request an attacker is able to modify
certain PHP environment variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series:
All versions prior to 20.4R3-S9; 21.1 versions 21.1R1 and later; 21.2 versions prior to 21.2R3-S7; 21.3 versions
prior to
21.3R3-S5; 21.4 versions
prior to
21.4R3-S5; 22.1 versions
prior to
22.1R3-S4; 22.2 versions
prior to
22.2R3-S2; 22.3 versions
prior to 22.3R3-S1; 22.4 versions
prior to
22.4R2-S2, 22.4R3; 23.2 versions prior to
23.2R1-S1, 23.2R2.
Other sources
Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables, leading to partial loss of integrity, which may allow chaining to other vulnerabilities.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-36844?
CVE-2023-36844 has been classified as a critical vulnerability due to its potential for remote code execution and unauthenticated access.
How do I fix CVE-2023-36844?
To mitigate CVE-2023-36844, it is recommended to update to the patched versions of Junos OS as specified in official security advisories.
Which Juniper products are affected by CVE-2023-36844?
CVE-2023-36844 affects Junos OS running on various EX Series switches and SRX Series firewalls.
Can CVE-2023-36844 be exploited remotely?
Yes, CVE-2023-36844 can be exploited by unauthenticated, network-based attackers to modify sensitive environment variables.
What versions of Junos OS are vulnerable to CVE-2023-36844?
Junos OS versions prior to 20.4 and certain newer revisions listed in the advisories are vulnerable to CVE-2023-36844.