iTnews Asia
  • Home
  • News
  • Networking

Juniper web management interface open to RCE

Juniper web management interface open to RCE

Two Junos OS versions get patches.

By Richard Chirgwin on Aug 21, 2023 11:52AM

Juniper Networks is warning of four vulnerabilities in two versions of its Junos OS operating system, which can be chained for unauthenticated remote code execution (RCE).

The “out of cycle” bulletin covers Junos OS on SRX and EX systems, and were discovered by an unnamed third party researcher.

The chain comprises four individual vulnerabilities: CVE-2023-36844, CVE-2023-36845, CVE-2023-36846, and CVE-2023-36847.

On their own, each of these vulnerabilities only rates a CVSS score of 5.3 (medium), but chained, they score 9.8 (critical).

CVE-2023-36844 is a PHP external variable modification vulnerability in the J-Web interface in Junos OS on EX.

It allows the attacker to “control certain, important environment variables”, and with a crafted request, the attacker could chain the bug to other vulnerabilities.

CVE-2023-36845 is a similar PHP bug in Junos OS on SRX systems.

CVE-2023-36846 and CVE-2023-36847 are missing authentication bugs on SRX and EX, respectively: “With a specific request that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.”

Fixes are available for affected versions.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
juniper networks junos os networking software

Related Articles

  • Philippines’ Security Bank modernises eKYC for secure customer onboarding
  • The outlook for software development in 2025
  • Malaysia launches national AI office for policy, regulation
  • Semyung University transforms IT infrastructure with NetApp
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

SATS to embed IoT, automation in S$150m 'food hub'

SATS to embed IoT, automation in S$150m 'food hub'

IMDA launches accelerator to help Poly and ITE students land tech jobs

IMDA launches accelerator to help Poly and ITE students land tech jobs

Malaysia's digital super highway fibre network gets gear boost

Malaysia's digital super highway fibre network gets gear boost

Shangri-La Group's Jen hotels implement smart check-in kiosks

Shangri-La Group's Jen hotels implement smart check-in kiosks

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.