← Back to CVE List
Vulnerability Intelligence Report
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable

CVE-2023-36845

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code. This issue affects Juniper Networks Junos OS on EX Series and SRX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3-S1; * 22.4 versions prior to 22.4R2-S1, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:93.55%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-473 ↗CWE-473 PHP External Variable Modification

Affected Products & Versions

Vendor Product Affected Versions
Juniper Networks Junos OS 0 < 20.4R3-S9 (affected), 21.1 < 21.1* (affected), 21.2 < 21.2R3-S7 (affected), 21.3 < 21.3R3-S5 (affected), 21.4 < 21.4R3-S5 (affected), 22.1 < 22.1R3-S4 (affected), 22.2 < 22.2R3-S2 (affected), 22.3 < 22.3R2-S2, 22.3R3-S1 (affected), 22.4 < 22.4R2-S1, 22.4R3 (affected), 23,2 < 23.2R1-S1, 23.2R2 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
93.546%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityJuniper Networks, Inc. · Vendor · USA
Reserved2023-06-27T16:17:25
Published2023-08-17T19:17:57
Patch Date2023-08-17
Last Updated2025-10-21T23:05:40

LINK COPIED TO CLIPBOARD