A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2023-36846

Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Published
2023-11-13
Modified
2026-07-31
Sources
cisa-kev

Summary

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.