LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-36851: Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 13, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-36851 to its Known Exploited Vulnerabilities catalog on Nov 13, 2023, with a federal patch deadline of Nov 17, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system…

CVE-2023-36851 is a missing authentication vulnerability in Juniper Junos OS on SRX Series devices. It allows an unauthenticated, network-based attacker to upload arbitrary files through the J-Web interface by sending a specific request to webauth_operation.php. This produces limited impact to file system integrity and may enable chaining to other issues. For organizations running Juniper SRX firewalls with J-Web exposed, the flaw matters because it removes a basic access control on a management path that should require authentication.

Defenders should treat any internet-facing or poorly segmented J-Web instance as high priority until the vendor-recommended mitigations or updates are confirmed in place. Specifics such as exact fixed releases must be verified against the official Juniper advisory.

How it works

The weakness is classified as CWE-306, Missing Authentication for Critical Function. In this case the critical function is file-upload handling inside the J-Web component of Junos OS on SRX Series platforms. An attacker who can reach the web interface can issue a crafted request directly to webauth_operation.php; that endpoint does not enforce authentication. The request permits the upload of arbitrary files, resulting in a loss of integrity for a portion of the device file system. Because the upload succeeds without credentials, the attacker gains a foothold that can be combined with other vulnerabilities for greater impact. No further exploit mechanics are required to understand the risk: the absence of an authentication check on a privileged management operation is sufficient for unauthenticated network abuse.

Am I affected? How to find it in your systems

The vulnerability affects Juniper Junos OS running on SRX Series devices that expose the J-Web management interface. These appliances are commonly deployed as perimeter or internal firewalls, so inventory should begin with every SRX unit in the environment.

If J-Web is reachable from untrusted networks, treat the device as potentially exposed until proven otherwise.

How to remediate

The primary remediation is to apply the vendor-supplied update or mitigation instructions for Junos OS on SRX Series. Follow the exact steps published by Juniper; CISA’s required action is to apply those mitigations or to discontinue use of the product if mitigations cannot be obtained. After patching, re-verify that J-Web authentication is enforced and that the previously unauthenticated upload path is no longer reachable. As additional hardening for this class of missing-authentication flaws, restrict management interfaces to dedicated administrative networks, enforce multi-factor authentication where supported, and disable unused web services. Regularly audit configuration to ensure J-Web remains disabled when not required for operations.

If you can't patch immediately

Until the official update can be installed, reduce exposure with compensating controls:

These measures lower the likelihood of successful exploitation but do not replace the vendor fix.

If your data may have been exposed

Vulnerabilities that allow unauthenticated file uploads can be stepping stones to broader compromise. Although ransomware use of this specific CVE is not documented, any successful exploitation that alters file-system integrity should be treated as a potential breach precursor. Review device logs, network telemetry, and downstream systems for indicators of follow-on activity. Separately, individuals whose credentials or personal data may have been involved can run a free exposure scan of their email addresses against known breach data sets to determine whether those addresses appear in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedJuniper · Junos OS
WeaknessCWE-306
Added to CISA KEVNov 13, 2023
Federal patch deadlineNov 17, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities