CVE-2023-36844 is a PHP External Variable Modification vulnerability in the J-Web interface of Juniper Networks Junos OS on EX Series devices, allowing unauthenticated attackers to manipulate critical environment variables. This vulnerability has a CVSS score of 5.3 (MEDIUM), indicating a network-based attack with low complexity that can lead to partial data integrity loss and potentially chain to more severe vulnerabilities. It is actively exploited in the wild, with high EPSS and FAUCET Risk Scores, and has garnered significant community discussion and media coverage, including reports of a publicly available Proof-of-Concept exploit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.4:-:*:*:*:*:*:* | ||
20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.4:r1:*:*:*:*:*:* | ||
20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.4:r1-s1:*:*:*:*:*:* | ||
20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.4:r2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.