Proof-of-concept exploit code has been released against vulnerabilities in Juniper SRX firewalls, which could allow hackers to remotely execute code in Juniper's JunOS on unpatched devices.

See also: MalDoc in PDF: Hide malicious Word files in PDFs
Juniper disclosed four moderate-severity issues in its EX switches and SRX firewalls and released security patches two weeks ago.
The security vulnerabilities were identified in the PHP-based J-Web interface, which administrators can use to manage and configure Juniper devices on their networks.
Security researchers at watchTowr Labs have since developed and released a proof-of-concept (PoC) exploit that bridges the SRX firewall flaws, a missing authentication check for critical operation vulnerability (CVE-2023-36846), and a PHP external variable modification flaw (CVE-2023-36845).
They also published a technical analysis describing the vulnerability analysis and PoC development process.
As they revealed, the pre-authentication upload flaw CVE-2023-36846 allows the unauthorized upload of a PHP file to a restricted directory using random names. A PHP configuration file is also uploaded to load the first file via auto_prepend_file in the second step.
See also: Is the FIN8 hacking group attacking Citrix NetScaler systems?
Handling environment variables requested over HTTP, such as PHPRC, by exploiting the CVE-2023-36845 flaw, helps load the configuration file, triggering the execution of the PHP file downloaded in the first step.
Although Juniper has not provided information about active exploitation of the vulnerabilities, WatchTowr Labs researchers expect that attackers will soon begin targeting unpatched Juniper devices in large-scale attacks.
Administrators are encouraged to apply Juniper updates or upgrade JunOS to the latest version or, at the very least, implement the vendor-recommended workarounds as soon as possible
See also: Spain: Phishing emails distribute LockBit Locker ransomware
In June, CISA issued its first binding operational directive (BOD) of the year, ordering US federal agencies to secure network equipment exposed to the Internet or misconfigured, such as Juniper firewalls and switches, within two weeks of discovery.
Information source: bleepingcomputer.com
