Input validation error in Junos OS - CVE-2023-36844

 

Input validation error in Junos OS - CVE-2023-36844

Published: August 18, 2023 / Updated: November 13, 2023


Vulnerability identifier: #VU79687
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-36844
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to modify application behavior.

The vulnerability exists due to insufficient validation of user-supplied input in J-Web. A remote attacker can modify values of certain PHP environments variables and modify application's behavior.

Successful exploitation of the vulnerability can lead to remote code execution.


Affected software

Junos OS

How to mitigate CVE-2023-36844

Install updates from vendor's website.

Junos OS - addressed in versions 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S4, 21.4R3-S5, 22.1R3-S3, 22.2R3-S1, 22.2R3-S2, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3, 23.2R1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins