CVE Feed

    Dashboard / CVE / CVE-2023-36846

    CVE-2023-36846

    A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain  part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * All versions prior to 20.4R3-S8; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3.

    Published:Aug 17, 2023
    Last Modified:Feb 26, 2026
    EPS:Aug 17, 2023
    EPSS Score:0.94226
    CVSS Score:5.3

    CISA Notification

    Description

    A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain  part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * All versions prior to 20.4R3-S8; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3.

    Required Action:

    Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Nov 17, 2023
    1029 days ago
    Alert Date
    Nov 13, 2023
    1033 days ago

    Affected Products

    Vendor
    Juniper
    Product
    Junos
    Vendor
    Juniper
    Product
    Srx100
    Vendor
    Juniper
    Product
    Srx110
    Vendor
    Juniper
    Product
    Srx1400
    Vendor
    Juniper
    Product
    Srx1500
    Vendor
    Juniper
    Product
    Srx210
    Vendor
    Juniper
    Product
    Srx220
    Vendor
    Juniper
    Product
    Srx240
    Vendor
    Juniper
    Product
    Srx240h2
    Vendor
    Juniper
    Product
    Srx240m
    Vendor
    Juniper
    Product
    Srx300
    Vendor
    Juniper
    Product
    Srx320
    Vendor
    Juniper
    Product
    Srx340
    Vendor
    Juniper
    Product
    Srx3400
    Vendor
    Juniper
    Product
    Srx345
    Vendor
    Juniper
    Product
    Srx3600
    Vendor
    Juniper
    Product
    Srx380
    Vendor
    Juniper
    Product
    Srx4000
    Vendor
    Juniper
    Product
    Srx4100
    Vendor
    Juniper
    Product
    Srx4200
    Vendor
    Juniper
    Product
    Srx4600
    Vendor
    Juniper
    Product
    Srx5000
    Vendor
    Juniper
    Product
    Srx5400
    Vendor
    Juniper
    Product
    Srx550
    Vendor
    Juniper
    Product
    Srx550 Hm
    Vendor
    Juniper
    Product
    Srx550m
    Vendor
    Juniper
    Product
    Srx5600
    Vendor
    Juniper
    Product
    Srx5800
    Vendor
    Juniper
    Product
    Srx650

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High