CVE-2023-36851

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
27/09/2023
Last modified:
27/01/2025

Description

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity.<br /> <br /> <br /> <br /> With a specific request to <br /> <br /> webauth_operation.php<br /> <br /> that doesn&amp;#39;t require authentication, an attacker is able to upload and download arbitrary files via J-Web, leading to a loss of <br /> <br /> integrity or confidentiality, which may allow chaining to other vulnerabilities.<br /> <br /> <br /> This issue affects Juniper Networks Junos OS on SRX Series:<br /> <br /> <br /> <br /> * <br /> <br /> 21.2 versions prior to 21.2R3-S8;<br /> * 21.4 <br /> <br /> versions prior to <br /> <br /> 21.4R3-S6;<br /> * 22.1 <br /> <br /> versions prior to <br /> <br /> 22.1R3-S5;<br /> * 22.2 <br /> <br /> versions prior to <br /> <br /> 22.2R3-S3;<br /> * 22.3 <br /> <br /> versions prior to <br /> <br /> 22.3R3-S2;<br /> * 22.4 versions prior to 22,4R2-S2, 22.4R3;<br /> * 23.2 versions prior to <br /> <br /> 23.2R1-S2, 23.2R2.<br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:juniper:junos:21.2:-:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r1-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r1-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r2-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r2-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r3:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r3-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r3-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r3-s3:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r3-s4:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r3-s5:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r3-s6:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:21.2:r3-s7:*:*:*:*:*:*