← العودة للجدول
CVE-2023-36845
CVE-2023-36845 — A PHP External Variable Modification vulnerability in J-Web of Juniper Networks
📅 2023-08-17
🔴 Critical 🔥 Yes NVD Exploit Network CVSS 9.8 🎯 EPSS 94.36%

📋 الوصف الكامل

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code. This issue affects Juniper Networks Juno

💻 الأنظمة المتأثرة

Juniper JunOS

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2023-36845

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v20.4

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←