Update – November 8th 2023: Juniper SIRT is now aware of successful exploitation of these vulnerabilities. Customers are urged to immediately upgrade.Update - September 26th 2023: A variation of the exploit for the code execution vulnerability (CVE-2023-36845) has been published that works without a previous file upload. Therefore it is important to fix the ability to execute code. Once this is prevented, the impact of the remaining issues is significantly reduced.Update - September 5th 2023: A new variant of the SRX upload vulnerability has been published by external researchers (CVE-2023-36851). All fixes listed under Solution below break the RCE chain: The EX releases fix the upload vulnerability and are unaffected by this new variant. The SRX releases are affected by the new file upload vulnerability but not the RCE. Juniper urges customers to upgrade to the releases listed below or apply a workaround until a fix becomes available.Additional fixes are being prepared. This JSA will be updated as new fixed releases become available.
Multiple vulnerabilities in the J-Web component of Juniper Networks Junos OS on SRX Series and EX Series have been resolved through the application of specific fixes to address each vulnerability.
These issues affect Juniper Networks Junos OS on SRX Series and EX Series:
These issues were discovered during external security research.
The following minimal configuration must be present on the device:
[system services web-management http]
or
[system services web-management https]
Juniper SIRT is aware of successful malicious exploitation of these vulnerabilities.The specific issues reported and resolved are listed below:
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.
2023-08-17: Initial publication 2023-08-23: Added version 21.1 explicitly as affected and not fixed (it's EoE) 2023-08-25: Corrected Related Information links 2023-08-30: Update on exploitation, explicitly added affected configuration 2023-09-05: Important update for SRX customers 2023-09-07: Corrected the link to PR 1758332 2023-09-26: Important update on a variant of CVE-2023-36845 2023-11-08: Juniper SIRT is now aware of successful exploitation