CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2023-36845

CVSS 9.8v3.1pub. 2023-08-17upd. 2025-10-24

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code. This issue affects Juniper Networks Junos OS on EX Series and SRX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3-S1; * 22.4 versions prior to 22.4R2-S1, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Juniper Junos

    OS
    Juniper
    20.421.121.221.321.422.122.222.322.423.2< 20.4
  • Juniper Srx100

    HW
    Juniper
    all versions
  • Juniper Srx110

    HW
    Juniper
    all versions
  • Juniper Srx1400

    HW
    Juniper
    all versions
  • Juniper Srx1500

    HW
    Juniper
    all versions
  • Juniper Srx210

    HW
    Juniper
    all versions
  • Juniper Srx220

    HW
    Juniper
    all versions
  • Juniper Srx240

    HW
    Juniper
    all versions
  • Juniper Srx240h2

    HW
    Juniper
    all versions
  • Juniper Srx240m

    HW
    Juniper
    all versions
  • Juniper Srx300

    HW
    Juniper
    all versions
  • Juniper Srx320

    HW
    Juniper
    all versions
  • Juniper Srx340

    HW
    Juniper
    all versions
  • Juniper Srx3400

    HW
    Juniper
    all versions
  • Juniper Srx345

    HW
    Juniper
    all versions
  • Juniper Srx3600

    HW
    Juniper
    all versions
  • Juniper Srx380

    HW
    Juniper
    all versions
  • Juniper Srx4000

    HW
    Juniper
    all versions
  • Juniper Srx4100

    HW
    Juniper
    all versions
  • Juniper Srx4200

    HW
    Juniper
    all versions
  • Juniper Srx4600

    HW
    Juniper
    all versions
  • Juniper Srx5000

    HW
    Juniper
    all versions
  • Juniper Srx5400

    HW
    Juniper
    all versions
  • Juniper Srx550

    HW
    Juniper
    all versions
  • Juniper Srx550 Hm

    HW
    Juniper
    all versions
  • Juniper Srx550m

    HW
    Juniper
    all versions
  • Juniper Srx5600

    HW
    Juniper
    all versions
  • Juniper Srx5800

    HW
    Juniper
    all versions
  • Juniper Srx650

    HW
    Juniper
    all versions

CISA KEV — detailsi

Vendori
Juniper
Producti
Junos OS
Added to KEVi
November 13, 2023
Remediation deadline (US Federal)i
November 17, 2023(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 17 listopada 2023
CWE
References

Related vulnerabilities

CVE-2024-21591CRITICAL9.8PL ✓same product

Out-of-bounds Write w J-Web Juniper Junos OS — RCE z uprawnieniami root

CVE-2021-0254CRITICAL9.8PL ✓same product

Buffer overflow w usłudze overlayd Juniper Junos OS — RCE i DoS

CVE-2021-0248CRITICAL10.0PL ✓same product

Hard-coded Credentials w Juniper Junos OS na urządzeniach NFX Series

CVE-2021-0211CRITICAL10.0PL ✓same product

Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message

CVE-2020-1654CRITICAL9.8PL ✓same product

RCE i DoS w Juniper SRX przez podatność usługi ICAP redirect