iTnews Asia
  • Home
  • News
  • Networking

Juniper Networks acknowledges new spin on firewall vulnerability

Juniper Networks acknowledges new spin on firewall vulnerability

Patches against fileless RCE.

By Richard Chirgwin on Sep 27, 2023 12:23PM

A vulnerability in Juniper Networks’ EX switches and SRX firewalls that first emerged in August is in the spotlight again, with researchers disclosing a fileless exploit that doesn’t require bug-chaining.

The original advisory was that three lower-rated bugs became critical if chained together, and watchTwr demonstrated how two of the bugs - CVE-2023-36845 and CVE-2023-36846 - could be exploited for remote code execution (RCE) on some devices.

On September 18, VulnCheck’s Jacob Bains went a step further, claiming one of the CVEs, CVE-2023-36845, could be exploited without chaining.

Bains said that VulnCheck’s proof-of-concept delivered RCE on the SRX firewalls without chaining any of the other vulnerabilities.

VulnCheck’s attack also works without the attacker needing to drop a file on the target machine. It  uses PHP’s auto_prepend_file and allow_url_include functions.

Juniper has now confirmed VulnCheck’s work in an out-of-cycle security bulletin.

“A variation of the exploit for the code execution vulnerability (CVE-2023-36845) has been published that works without a previous file upload,” Juniper’s advisory stated.

“Therefore it is important to fix the ability to execute code”.

All supported versions of Junos OS have been patched.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
juniper networking security

Related Articles

  • Your organisation’s physical security can be a gateway for cybercriminals
  • The best way to outsmart your threat actors is to think like one
  • How cybercriminals are exploiting LLMs to harm your business
  • Is identity now the next parameter of cybersecurity breaches?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Shangri-La Group's Jen hotels implement smart check-in kiosks

Shangri-La Group's Jen hotels implement smart check-in kiosks

Malaysia's digital super highway fibre network gets gear boost

Malaysia's digital super highway fibre network gets gear boost

Sime Darby to partner Equinix for digital transformation

Sime Darby to partner Equinix for digital transformation

TIME dotCom to use cyber security mesh platform

TIME dotCom to use cyber security mesh platform

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.