Database/Firmware, BMC & network fabric
Juniper Junos OS J-Web (EX): PHP external variable modification
CVSS 5.3CVE-2023-36844Firmware, BMC & network fabricKnown exploitedcurated
Impact
PHP external variable modification; part of the exploited J-Web chain
Who can reach it
Network, unauthenticated
What to do
Junos upgrade with switch failover
References
Related entries
- Juniper Junos OS J-Web (EX): Missing authentication on `installAppPackage.php` — unauthenticated file upload to theCVE-2023-36847 · Juniper Junos OS J-Web (EX)Medium
- Linux KVM - SEV-ES/SEV-SNP VMGEXIT double-fetch race: A KVM guest running SEV-ES or SEV-SNP with several vCPUs canCVE-2023-4155 · Linux KVM - SEV-ES/SEV-SNP VMGEXIT double-fetch raceMedium
- GRUB2 (NTFS filesystem parser): Out-of-bounds read in the same NTFS path leaks GRUB heap memoryCVE-2023-4693 · GRUB2 (NTFS filesystem parser)Medium
- Schneider Electric Galaxy VS / VL / VXL three-phase UPS, Network Management Card over HTTPS: Path traversal letsCVE-2023-6032 · Schneider Electric Galaxy VS / VL / VXL three-phase UPS, Network Management Card over HTTPSMedium
- Dell PowerEdge Server BIOS (AMD platforms, TOCTOU race): A time-of-check/time-of-use race in BIOS givesCVE-2024-0171 · Dell PowerEdge Server BIOS (AMD platforms, TOCTOU race)Medium
- Arista EOS (MACsec with egress ACLs): On interfaces with both MACsec and egress ACLs configured, the egress ACL is notCVE-2024-27891 · Arista EOS (MACsec with egress ACLs)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.