S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-36844 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in Juniper Networks Junos OS affects v. prior to 20.4R3-S9; 21.1 versions 21.1R1 and later; 21.2 versions prior to 21.2R3-S7; 21.3 versions prior to 21.3R3-S5; 21.4 versions prior to 21.4R3-S5; 22.1 versions prior to 22.1R3-S4; 22.2 versions prior to 22.2R3-S2; 22.3 versions prior to 22.3R3-S1; 22.4 versions prior to 22.4R2-S2, 22.4R3; 23.2 versions prior to 23.2R1-S1, 23.2R2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-36844
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R3-S1; * 22.4 versions prior to 22.4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Junos OSby Juniper Networks
AFFECTED< 20.4R3-S9SAFE ✓≥ 20.4R3-S9
Updated Aug 22, 2026View on NVD →
Detail

Juniper Networks Junos OS is an operating system used for networking and security devices such as switches, routers, and firewalls. It is highly popular among network professionals due to its robust capabilities and reliability in managing complex tasks. The OS is known for its advanced networking features, such as routing, switching, and security protocols.

One of the latest vulnerabilities discovered in Juniper Networks Junos OS is the CVE-2023-36844. This external variable modification vulnerability exists in the J-Web feature of Junos OS on EX Series. It is a network-based attack that allows unauthenticated access to control important environment variables. An attacker can manipulate specific PHP environment variables using a crafted request, resulting in partial loss of integrity and possibly leading to other vulnerabilities.

When CVE-2023-36844 is exploited, it can result in severe security implications, causing partial loss of integrity and access control on the targeted environment. The vulnerability can be chained with other weaknesses, leading to a complete loss of data confidentiality and system integrity. In a worst-case scenario, it can lead to system takeover and network compromise, causing major disruptions and financial losses.

With the pro features of the s4e.io platform, users can quickly learn about vulnerabilities that may exist within their digital assets. The platform can identify security weaknesses, provide guidance on remediation, and offer 24/7 monitoring to help mitigate risks. By leveraging such advanced security tools, organizations can significantly reduce the likelihood of potential threats, ensuring the safety and integrity of their digital infrastructure.

 

REFERENCES

Solution Advice

Organizations can take the following precautions to protect against this vulnerability in Juniper Networks Junos OS:

  • Ensure systems are up-to-date with the latest software patches and updates.
  • Use advanced security measures such as firewalls, IDS, and IPS to monitor network traffic for suspicious activities.
  • Restrict and limit access control, including only allowing access to authorized personnel.
  • Regularly audit the system logs and monitor for any anomalous activities that may indicate a potential attack.
  • Engage in security training and awareness programs for employees.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-36844 scanner - Remote Code Execution (RCE) vulnerability in Juniper Networks Junos OS | S4E