CVE-2023-36845
CRITICALA PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series
and SRX Series
allows an unauthenticated, network-based attacker to remotely execute code.
Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code.
This issue affects Juniper Networks Junos OS on EX Series
and
SRX Series:
- All versions prior to
20.4R3-S9;
- 21.1 versions 21.1R1 and later;
- 21.2 versions prior to 21.2R3-S7;
- 21.3 versions prior to 21.3R3-S5;
- 21.4 versions prior to 21.4R3-S5;
- 22.1 versions
prior to
22.1R3-S4;
- 22.2 versions
prior to
22.2R3-S2;
- 22.3 versions
prior to
22.3R2-S2, 22.3R3-S1;
- 22.4 versions
prior to
22.4R2-S1, 22.4R3;
- 23.2 versions prior to 23.2R1-S1, 23.2R2.
Affected Products
junosjuniperResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
A PHP External Variable Modification vulnerability in J-Web of Juniper N…
A PHP External Variable Modification vulnerability in J-Web of Juniper N…
A PHP External Variable Modification vulnerability in J-Web of Juniper N…
A PHP External Variable Modification vulnerability in J-Web of Juniper N…
A PHP External Variable Modification vulnerability in J-Web of Juniper N…
A PHP External Variable Modification vulnerability in J-Web of Juniper N…
A PHP External Variable Modification vulnerability in J-Web of Juniper N…
A PHP External Variable Modification vulnerability in J-Web of Juniper N…
A PHP External Variable Modification vulnerability in J-Web of Juniper N…
A PHP External Variable Modification vulnerability in J-Web of Juniper N…
Frequently Asked Questions
Is CVE-2023-36845 in your stack?
O3 detects CVE-2023-36845 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.