CVE-2023-36846 is a critical Missing Authentication vulnerability in Juniper Networks Junos OS on SRX Series devices. It allows an unauthenticated attacker to upload arbitrary files via J-Web, compromising file system integrity. Rated 5.3 MEDIUM on CVSS, its high EPSS and FAUCET scores, along with its inclusion in CISA's KEV catalog, indicate significant risk. This vulnerability is actively exploited in the wild, with public exploit code available and extensive community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.4:-:*:*:*:*:*:* | ||
20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.4:r1:*:*:*:*:*:* | ||
20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.4:r1-s1:*:*:*:*:*:* | ||
20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.4:r2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.