Database/Firmware, BMC & network fabric
Juniper Junos OS J-Web (EX/SRX): **[KEV]** Unauthenticated remote code execution by setting `PHPRC` through a crafted
CVE-2023-36845Firmware, BMC & network fabricKnown exploitedcurated
Impact
**[KEV]** Unauthenticated remote code execution by setting PHPRC through a crafted J-Web request; chained with the other J-Web bugs for full device takeover
Who can reach it
Network, unauthenticated
What to do
Junos upgrade or disabling J-Web entirely; on a management-plane switch the fastest mitigation is turning J-Web off, which removes the GUI ops staff depend on
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.