iTnews Asia
  • Home
  • News
  • Networking

Juniper Networks acknowledges new spin on firewall vulnerability

Juniper Networks acknowledges new spin on firewall vulnerability

Patches against fileless RCE.

By Richard Chirgwin on Sep 27, 2023 12:23PM

A vulnerability in Juniper Networks’ EX switches and SRX firewalls that first emerged in August is in the spotlight again, with researchers disclosing a fileless exploit that doesn’t require bug-chaining.

The original advisory was that three lower-rated bugs became critical if chained together, and watchTwr demonstrated how two of the bugs - CVE-2023-36845 and CVE-2023-36846 - could be exploited for remote code execution (RCE) on some devices.

On September 18, VulnCheck’s Jacob Bains went a step further, claiming one of the CVEs, CVE-2023-36845, could be exploited without chaining.

Bains said that VulnCheck’s proof-of-concept delivered RCE on the SRX firewalls without chaining any of the other vulnerabilities.

VulnCheck’s attack also works without the attacker needing to drop a file on the target machine. It  uses PHP’s auto_prepend_file and allow_url_include functions.

Juniper has now confirmed VulnCheck’s work in an out-of-cycle security bulletin.

“A variation of the exploit for the code execution vulnerability (CVE-2023-36845) has been published that works without a previous file upload,” Juniper’s advisory stated.

“Therefore it is important to fix the ability to execute code”.

All supported versions of Junos OS have been patched.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
juniper networking security

Related Articles

  • Best practice tips for secure password management
  • Are third-party blind spots the weakest link in enterprise cybersecurity chain?
  • Five tips a CIO or CSO should know to stop employee-driven IP theft
  • StarHub launches app to protect customers from scam calls and SMS
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

IMDA launches accelerator to help Poly and ITE students land tech jobs

IMDA launches accelerator to help Poly and ITE students land tech jobs

Indosat Ooredoo Hutchison signs on to Edgio

Indosat Ooredoo Hutchison signs on to Edgio

NTT Docomo ties up with Vodafone UK to progress Open RAN

NTT Docomo ties up with Vodafone UK to progress Open RAN

US lawmakers introduce bill to restrict Huawei's access to banks

US lawmakers introduce bill to restrict Huawei's access to banks

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.