LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-36847: Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 13, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-36847 to its Known Exploited Vulnerabilities catalog on Nov 13, 2023, with a federal patch deadline of Nov 17, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system…

CVE-2023-36847 is a missing authentication vulnerability in Juniper Junos OS on EX Series devices. An unauthenticated, network-based attacker can send a specific request to installAppPackage.php and upload arbitrary files through the J-Web interface. This produces limited impact to file system integrity and may enable chaining to other vulnerabilities. For network teams running EX Series switches with J-Web exposed, the issue matters because it removes a basic access control on a management path that is often reachable from internal or semi-trusted segments.

Public detail is limited to the CISA description; exact affected releases, CVSS values, and full exploit conditions must be confirmed against the vendor advisory. Known ransomware use is not documented.

How it works

The weakness is classified as CWE-306 (Missing Authentication for Critical Function). In this case the critical function is the J-Web endpoint installAppPackage.php. Because authentication is not enforced for that request, an attacker who can reach the J-Web service can upload arbitrary files. The result is a loss of integrity for a portion of the file system. The CISA summary notes that this integrity loss may allow the attacker to chain the upload to additional vulnerabilities on the same device. No further exploit mechanics, payload formats, or privilege-escalation steps are provided in the available facts; defenders should treat any unauthenticated file-write capability on a management interface as a high-priority foothold risk and verify the precise attack surface in the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects Juniper Junos OS running on EX Series switches when the J-Web interface is enabled. EX Series devices are commonly deployed as access or aggregation switches in campus and data-center networks; J-Web is the web-based management GUI that may be left enabled by default or for operational convenience.

If J-Web is disabled or unreachable from attacker-controlled networks, the practical attack surface is reduced, but confirmation still requires checking the advisory for any residual conditions.

How to remediate

The primary remediation is to apply the vendor-supplied update for Junos OS on EX Series as directed in the Juniper advisory. CISA’s required action is to apply mitigations per vendor instructions or to discontinue use of the product if mitigations are unavailable. After patching:

Document the change window and retain evidence of the applied software version for compliance and audit purposes.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls appropriate to a missing-authentication file-upload flaw:

These measures lower the likelihood of successful exploitation but do not eliminate the underlying missing-authentication condition; schedule the official patch as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to device compromise and subsequent lateral movement or data exposure. Known ransomware use is not documented for CVE-2023-36847. If you suspect the device was reached before remediation, treat the switch as potentially untrusted: isolate it, collect forensic images, and review adjacent systems for follow-on activity. As a general hygiene step, you can run a free exposure scan of your email addresses against known breach data sets to determine whether any associated credentials have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedJuniper · Junos OS
WeaknessCWE-306
Added to CISA KEVNov 13, 2023
Federal patch deadlineNov 17, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities