iTnews Asia
  • Home
  • News
  • Networking

Juniper web management interface open to RCE

Juniper web management interface open to RCE

Two Junos OS versions get patches.

By Richard Chirgwin on Aug 21, 2023 11:52AM

Juniper Networks is warning of four vulnerabilities in two versions of its Junos OS operating system, which can be chained for unauthenticated remote code execution (RCE).

The “out of cycle” bulletin covers Junos OS on SRX and EX systems, and were discovered by an unnamed third party researcher.

The chain comprises four individual vulnerabilities: CVE-2023-36844, CVE-2023-36845, CVE-2023-36846, and CVE-2023-36847.

On their own, each of these vulnerabilities only rates a CVSS score of 5.3 (medium), but chained, they score 9.8 (critical).

CVE-2023-36844 is a PHP external variable modification vulnerability in the J-Web interface in Junos OS on EX.

It allows the attacker to “control certain, important environment variables”, and with a crafted request, the attacker could chain the bug to other vulnerabilities.

CVE-2023-36845 is a similar PHP bug in Junos OS on SRX systems.

CVE-2023-36846 and CVE-2023-36847 are missing authentication bugs on SRX and EX, respectively: “With a specific request that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.”

Fixes are available for affected versions.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
juniper networks junos os networking software

Related Articles

  • AI governance must evolve alongside adoption in APAC
  • 2026 a pivotal year for enterprises to deliver real value from AI
  • AI is triggering a structural reset in enterprise IT strategy
  • Vectorising the enterprise: Why 2026 is year of intelligent data platforms
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

TIME dotCom to use cyber security mesh platform

TIME dotCom to use cyber security mesh platform

TD Tawandang ties up with Google Cloud to serve mom and pop shops

TD Tawandang ties up with Google Cloud to serve mom and pop shops

Ericsson expects 5G subscriptions to cross one billion in 2022

Ericsson expects 5G subscriptions to cross one billion in 2022

SATS to embed IoT, automation in S$150m 'food hub'

SATS to embed IoT, automation in S$150m 'food hub'

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.