CVE-2023-36846: Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity.
With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of
integrity
for a certain
part of the file system, which may allow chaining to other vulnerabilities.
This issue affects Juniper Networks Junos OS on SRX Series:
All versions prior to 20.4R3-S8; 21.1 versions 21.1R1 and later; 21.2 versions prior to 21.2R3-S6; 21.3 versions
prior to
21.3R3-S5; 21.4 versions
prior to
21.4R3-S5; 22.1 versions
prior to
22.1R3-S3; 22.2 versions
prior to
22.2R3-S2; 22.3 versions
prior to
22.3R2-S2, 22.3R3; 22.4 versions
prior to
22.4R2-S1, 22.4R3.
Other sources
Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 20.4R3-S8 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 21.2R3-S6 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 21.3R3-S5 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 21.4R3-S5 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.1R3-S3 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.2R3-S2 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.3R2-S2 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.3R3 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.4R2-S1 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.4R3 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 23.2R1 - Compensating control
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-36846?
CVE-2023-36846 has been classified with a low severity level affecting the file system integrity due to a missing authentication vulnerability.
How do I fix CVE-2023-36846?
To address CVE-2023-36846, update your Junos OS software to the latest version recommended by Juniper Networks.
What products are affected by CVE-2023-36846?
CVE-2023-36846 affects Juniper Networks' Junos OS on SRX Series and EX Series devices.
What kind of attacks can be executed using CVE-2023-36846?
Exploitation of CVE-2023-36846 allows unauthenticated attackers to impact the file system integrity of the affected devices.
Is CVE-2023-36846 being actively exploited in the wild?
As of the latest updates, there is no information indicating that CVE-2023-36846 is being actively exploited.