CVE-2023-36847

KEV
Published: Ago 17, 2023 Last Modified: Feb 26, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,3
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none

Description

AI Translation Available

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity.

With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of

integrity

for a certain

part of the file system, which may allow chaining to other vulnerabilities.

This issue affects Juniper Networks Junos OS on EX Series:

* All versions prior to 20.4R3-S8;
* 21.1 versions 21.1R1 and later;
* 21.2 versions prior to 21.2R3-S6;
* 21.3 versions

prior to

21.3R3-S5;
* 21.4 versions

prior to

21.4R3-S4;
* 22.1 versions

prior to

22.1R3-S3;
* 22.2 versions

prior to

22.2R3-S1;
* 22.3 versions

prior to

22.3R2-S2, 22.3R3;
* 22.4 versions

prior to

22.4R2-S1, 22.4R3.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,9404
Percentile
1,0th
Updated

EPSS Score Trend (Last 90 Days)

306

Missing Authentication for Critical Function

Draft
Common Consequences
Security Scopes Affected:
Access Control Other
Potential Impacts:
Gain Privileges Or Assume Identity Varies By Context
Applicable Platforms
Technologies: Cloud Computing, ICS/OT
View CWE Details
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.1:r2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:r1-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.2:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.1:r3-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:r3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.4:r2-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.4:r3-s3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.3:r1-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.4:r3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.4:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:r3-s6:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.3:r1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:r3-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.1:r2-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:r1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.2:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.4:r2-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.2:r3-s5:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.3:r3-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:r3-s5:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.4:r1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.3:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.2:r1-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.3:r1-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.1:r2-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.2:r1-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:r2-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.2:r1-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.2:r3-s3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.4:r1-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.3:r3-s4:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.1:r1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.4:r2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:r3-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.2:r2-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.4:r1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.1:r3-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.3:r2-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.4:r3-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.2:r2-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.3:r2-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.1:r3-s5:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.2:r3-s4:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.1:r3-s3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.3:r2-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.3:r3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.2:r3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.3:r2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.1:r3-s4:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.3:r1-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.2:r2-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.4:r3-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.4:r1-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.1:r1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.3:r2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:r3-s4:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.1:r2-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.2:r3-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.1:r3-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.1:r2-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.4:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.2:r1-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.3:r3-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.3:r3-s3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:r3-s7:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.4:r1-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.4:r2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.1:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.2:r2-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.1:r3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.2:r1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:r2-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:r3-s3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.1:r3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.1:r1-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.1:r2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.2:r2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:20.4:r2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.4:r1-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.3:r1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.3:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.1:r3-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.2:r3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.1:r1-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.2:r2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

Version Range Affected
To 20.4 (exclusive)
cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.2:r3-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.2:r1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:21.1:r1-s1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Junos by Juniper

cpe:2.3:o:juniper:junos:22.3:r1-s2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023…
https://supportportal.juniper.net/JSA72300
https://supportportal.juniper.net/JSA72300