Input validation error in Junos OS - CVE-2023-36844
Published: August 18, 2023 / Updated: November 13, 2023
Vulnerability details
The vulnerability allows a remote attacker to modify application behavior.
The vulnerability exists due to insufficient validation of user-supplied input in J-Web. A remote attacker can modify values of certain PHP environments variables and modify application's behavior.
Successful exploitation of the vulnerability can lead to remote code execution.
Affected software
How to mitigate CVE-2023-36844
Links to Public Exploits and PoC-codes
- Exploit #9351 - CVE-2023-36844_Juniper_RCE (A Proof of Concept for chaining the CVEs [CVE-2023-36844, CVE-2023-36845, CVE-2023-36846, CVE-2023-36847] to achieve Remote Code Execution (phpinfo) in Juniper JunOS within SRX and EX Series products.Modified from original expl (September 27, 2023)
- Exploit #9269 - Juniper JunOS SRX / EX Remote Code Execution (August 31, 2023)
- Exploit #9263 - juniper-rce_cve-2023-36844 () (August 29, 2023)