HomeSecurityJuniper: Thousands of devices vulnerable to RCE flaws

Juniper: Thousands of devices vulnerable to RCE flaws

It is estimated that there are RCE vulnerabilities in approximately 12,000 Juniper SRX firewalls and EX switches , which allow remote code execution, without the required authentication, which attackers are exploiting .

See also: Exploit released for Juniper firewall bugs that allow RCE attacks

Juniper

In August, Juniper announced the flaws CVE-2023-36844, CVE-2023-36845, CVE-2023-36846, and CVE-2023-36847, which were rated as moderate severity with a score of 5.3. However, when these flaws are combined, they create a critical remote code execution flaw with a score of 9.8.

In a more recent technical report, WatchTowr Labs presented a PoC that combines the CVE-2023-36845 and CVE-2023-36846 flaws. This allows researchers to execute remote code by uploading two files to a vulnerable device . VulnCheck vulnerability researcher Jacob Baines released another PoC exploit that exploits only CVE-2023-36845, avoiding the need to upload files while still achieving remote code execution.

As part of Baines' report, a researcher shared a free scanner on GitHub intended to help identify vulnerable versions, revealing thousands of vulnerable devices exposed on the Internet.

“We demonstrated how CVE-2023-36845, a vulnerability marked as Medium severity by Juniper, can be exploited to remotely execute arbitrary code without authentication,” explains the VulnCheck.

“We have converted a multi-step exploit into an exploit that can be written using a single curl command and appears to affect more than just older systems.“

The impact of the identified security issue is widespread and severe, much more than the “moderate” CVSS score suggests. Administrators should take immediate action to remediate the vulnerability.

See also: 'ThemeBleed': Windows 11 RCE flaw gets PoC

RCE

Baines says he purchased an old Juniper SRX210 firewall to test the exploit, but found that his device lacked the do_fileUpload() required to upload files to the device. This essentially broke the watchTowr exploit chain, forcing the researcher to look for other possibilities for remote code execution.

Baines realized that you can avoid the need to upload two files to the server destinations by manipulating environment variables. The server is used to process HTTP requests from users via stdin while executing a set of CGI.

Taking advantage of this opportunity, attackers can trick the system into recognizing a fake “file,” /dev/fd/0. By changing the PHPRC environment variable and the HTTP request, they can gain access to sensitive data . The researcher then exploited the “ auto_prepend_file ” and “ allow_url_include ” functions to execute arbitrary PHP code via the data:// protocol without the need to upload files.

With this in mind, the severity rating of CVE-2023-36845, which is 5.4, should now be revised to a much higher one due to its ability to allow remote code execution.

The CVE-2023-36845 vulnerability affects the following versions of Junos OS on the EX series and SRX series:

All versions before 20.4R3-S8
21.1 version 21.1R1 and later
21.2 versions before 21.2R3-S6
21.3 versions before 21.3R3-S5
21.4 versions before 21.4R3-S5
22.1 versions before 22.1R3-S3 22.2 versions before 22.2R3-
S2
22.3 versions before 22.3R2-S2, 22.3R3
22.4 versions before 22.4R2-S1, 22.4R3

See also: KmsdBot malware upgraded: Now targets IoT devices

Remote Code Execution (RCE) is one of the most dangerous types of threats in cybersecurity, as it allows attackers to execute arbitrary code on a remote server or device. In the case of the Juniper flaw, RCE is even more threatening, as no authentication is required to execute the code. This means that attackers do not need to have access to valid credentials to exploit the flaw, significantly increasing the risk to vulnerable devices and systems.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS