Product Affected

These issues affect all versions of Junos OS on SRX Series and EX Series.
Critical
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Problem

Update – November 8th 2023:  Juniper SIRT is now aware of successful exploitation of these vulnerabilities.  Customers are urged to immediately upgrade.

Update - September 26th 2023: A variation of the exploit for the code execution vulnerability (CVE-2023-36845) has been published that works without a previous file upload. Therefore it is important to fix the ability to execute code. Once this is prevented, the impact of the remaining issues is significantly reduced.

Update - September 5th 2023: A new variant of the SRX upload vulnerability has been published by external researchers (CVE-2023-36851). All fixes listed under Solution below break the RCE chain: The EX releases fix the upload vulnerability and are unaffected by this new variant. The SRX releases are affected by the new file upload vulnerability but not the RCE. Juniper urges customers to upgrade to the releases listed below or apply a workaround until a fix becomes available.

Additional fixes are being prepared.  This JSA will be updated as new fixed releases become available.


Multiple vulnerabilities in the J-Web component of Juniper Networks Junos OS on SRX Series and EX Series have been resolved through the application of specific fixes to address each vulnerability.

 

These issues affect Juniper Networks Junos OS on SRX Series and EX Series:

  • All versions prior to 20.4R3-S9;
  • 21.1 version 21.1R1 and later versions;
  • 21.2 versions prior to 21.2R3-S7;
  • 21.3 versions prior to 21.3R3-S5;
  • 21.4 versions prior to 21.4R3-S5;
  • 22.1 versions prior to 22.1R3-S4;
  • 22.2 versions prior to 22.2R3-S2;
  • 22.3 versions prior to 22.3R2-S2, 22.3R3-S1;
  • 22.4 versions prior to 22.4R2-S1, 22.4R3;
  • 23.2 versions prior to 23.2R1-S1, 23.2R2.


These issues were discovered during external security research.
 

The following minimal configuration must be present on the device:

[system services web-management http]

or

[system services web-management https]


Juniper SIRT is aware of successful malicious exploitation of these vulnerabilities.

The specific issues reported and resolved are listed below:

CVECVSSSummary
CVE-2023-368445.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities.
CVE-2023-368459.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code.
CVE-2023-368465.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain  part of the file system, which may allow chaining to other vulnerabilities.
CVE-2023-368475.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

CVE-2023-368515.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

Solution

The following software releases have been updated to prevent the code execution (CVE-2023-36845): 20.4R3-S9, 21.2R3-S7*, 21.3R3-S5, 21.4R3-S5*, 22.1R3-S4, 22.2R3-S2, 22.3R2-S2, 22.3R3-S1, 22.4R2-S1, 22.4R3*, 23.2R1-S1, 23.2R2*, 23.4R1*, and all subsequent releases.
*Pending Publication

Software updates for the remaining vulnerabilities are coming. However, once the ability to execute code is prevented with the aforementioned releases, the impact of these remaining issues is significantly reduced.

These issues are being tracked as 1735387173538917369421736937. and 1758332.

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

Disable J-Web, or limit access to only trusted hosts.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2023-08-17: Initial publication
2023-08-23: Added version 21.1 explicitly as affected and not fixed (it's EoE)
2023-08-25: Corrected Related Information links
2023-08-30: Update on exploitation, explicitly added affected configuration
2023-09-05: Important update for SRX customers
2023-09-07: Corrected the link to PR 1758332
2023-09-26: Important update on a variant of CVE-2023-36845
2023-11-08: Juniper SIRT is now aware of successful exploitation


Related Information

Acknowledgements

The Juniper SIRT would like to acknowledge and thank LYS, working with DEVCORE Internship Program, for responsibly reporting the vulnerabilities CVE-2023-36844, CVE-2023-36845, CVE-2023-36846 and CVE-2023-36847.