CVE Feed

    Dashboard / CVE / CVE-2023-36844

    CVE-2023-36844

    A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R3-S1; * 22.4 versions prior to 22.4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2.

    Published:Aug 17, 2023
    Last Modified:Oct 24, 2025
    EPS:Aug 17, 2023
    EPSS Score:0.94302
    CVSS Score:5.3

    CISA Notification

    Description

    A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R3-S1; * 22.4 versions prior to 22.4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2.

    Required Action:

    Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Nov 17, 2023
    1029 days ago
    Alert Date
    Nov 13, 2023
    1033 days ago

    Affected Products

    Vendor
    Juniper
    Product
    Ex2200
    Vendor
    Juniper
    Product
    Ex2200-c
    Vendor
    Juniper
    Product
    Ex2200-vc
    Vendor
    Juniper
    Product
    Ex2300
    Vendor
    Juniper
    Product
    Ex2300-24mp
    Vendor
    Juniper
    Product
    Ex2300-24p
    Vendor
    Juniper
    Product
    Ex2300-24t
    Vendor
    Juniper
    Product
    Ex2300-48mp
    Vendor
    Juniper
    Product
    Ex2300-48p
    Vendor
    Juniper
    Product
    Ex2300-48t
    Vendor
    Juniper
    Product
    Ex2300-c
    Vendor
    Juniper
    Product
    Ex2300m
    Vendor
    Juniper
    Product
    Ex3200
    Vendor
    Juniper
    Product
    Ex3300
    Vendor
    Juniper
    Product
    Ex3300-vc
    Vendor
    Juniper
    Product
    Ex3400
    Vendor
    Juniper
    Product
    Ex4200
    Vendor
    Juniper
    Product
    Ex4200-vc
    Vendor
    Juniper
    Product
    Ex4300
    Vendor
    Juniper
    Product
    Ex4300-24p
    Vendor
    Juniper
    Product
    Ex4300-24p-s
    Vendor
    Juniper
    Product
    Ex4300-24t
    Vendor
    Juniper
    Product
    Ex4300-24t-s
    Vendor
    Juniper
    Product
    Ex4300-32f
    Vendor
    Juniper
    Product
    Ex4300-32f-dc
    Vendor
    Juniper
    Product
    Ex4300-32f-s
    Vendor
    Juniper
    Product
    Ex4300-48mp
    Vendor
    Juniper
    Product
    Ex4300-48mp-s
    Vendor
    Juniper
    Product
    Ex4300-48p
    Vendor
    Juniper
    Product
    Ex4300-48p-s
    Vendor
    Juniper
    Product
    Ex4300-48t
    Vendor
    Juniper
    Product
    Ex4300-48t-afi
    Vendor
    Juniper
    Product
    Ex4300-48t-dc
    Vendor
    Juniper
    Product
    Ex4300-48t-dc-afi
    Vendor
    Juniper
    Product
    Ex4300-48t-s
    Vendor
    Juniper
    Product
    Ex4300-48tafi
    Vendor
    Juniper
    Product
    Ex4300-48tdc
    Vendor
    Juniper
    Product
    Ex4300-48tdc-afi
    Vendor
    Juniper
    Product
    Ex4300-mp
    Vendor
    Juniper
    Product
    Ex4300-vc
    Vendor
    Juniper
    Product
    Ex4300m
    Vendor
    Juniper
    Product
    Ex4400
    Vendor
    Juniper
    Product
    Ex4500
    Vendor
    Juniper
    Product
    Ex4500-vc
    Vendor
    Juniper
    Product
    Ex4550
    Vendor
    Juniper
    Product
    Ex4550-vc
    Vendor
    Juniper
    Product
    Ex4550\/vc
    Vendor
    Juniper
    Product
    Ex4600
    Vendor
    Juniper
    Product
    Ex4600-vc
    Vendor
    Juniper
    Product
    Ex4650
    Vendor
    Juniper
    Product
    Ex6200
    Vendor
    Juniper
    Product
    Ex6210
    Vendor
    Juniper
    Product
    Ex8200
    Vendor
    Juniper
    Product
    Ex8200-vc
    Vendor
    Juniper
    Product
    Ex8208
    Vendor
    Juniper
    Product
    Ex8216
    Vendor
    Juniper
    Product
    Ex9200
    Vendor
    Juniper
    Product
    Ex9204
    Vendor
    Juniper
    Product
    Ex9208
    Vendor
    Juniper
    Product
    Ex9214
    Vendor
    Juniper
    Product
    Ex9250
    Vendor
    Juniper
    Product
    Ex9251
    Vendor
    Juniper
    Product
    Ex9253
    Vendor
    Juniper
    Product
    Junos

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High