A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code. This issue affects Juniper Networks Junos OS on EX Series and SRX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3-S1; * 22.4 versions prior to 22.4R2-S1, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HJuniper Junos
OSJuniper20.421.121.221.321.422.122.222.322.423.2< 20.4Juniper Srx100
HWJuniperall versionsJuniper Srx110
HWJuniperall versionsJuniper Srx1400
HWJuniperall versionsJuniper Srx1500
HWJuniperall versionsJuniper Srx210
HWJuniperall versionsJuniper Srx220
HWJuniperall versionsJuniper Srx240
HWJuniperall versionsJuniper Srx240h2
HWJuniperall versionsJuniper Srx240m
HWJuniperall versionsJuniper Srx300
HWJuniperall versionsJuniper Srx320
HWJuniperall versionsJuniper Srx340
HWJuniperall versionsJuniper Srx3400
HWJuniperall versionsJuniper Srx345
HWJuniperall versionsJuniper Srx3600
HWJuniperall versionsJuniper Srx380
HWJuniperall versionsJuniper Srx4000
HWJuniperall versionsJuniper Srx4100
HWJuniperall versionsJuniper Srx4200
HWJuniperall versionsJuniper Srx4600
HWJuniperall versionsJuniper Srx5000
HWJuniperall versionsJuniper Srx5400
HWJuniperall versionsJuniper Srx550
HWJuniperall versionsJuniper Srx550 Hm
HWJuniperall versionsJuniper Srx550m
HWJuniperall versionsJuniper Srx5600
HWJuniperall versionsJuniper Srx5800
HWJuniperall versionsJuniper Srx650
HWJuniperall versions
CISA KEV — detailsi
- Vendori
- Juniper
- Producti
- Junos OS
- Added to KEVi
- November 13, 2023
- Remediation deadline (US Federal)i
- November 17, 2023(overdue)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code.
Related vulnerabilities
Out-of-bounds Write w J-Web Juniper Junos OS — RCE z uprawnieniami root
Buffer overflow w usłudze overlayd Juniper Junos OS — RCE i DoS
Hard-coded Credentials w Juniper Junos OS na urządzeniach NFX Series
Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message
RCE i DoS w Juniper SRX przez podatność usługi ICAP redirect