Skip to content

CVE-2023-36846

Missing Authentication for Critical Function — is CVE-2023-36846real, exploitable, or a false positive? Here's the community ground truth.

Medium · CVSS 5.3EPSS 94.2%CISA KEVCWE-306 · Missing Authentication for Critical Function

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain  part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * All versions prior to 20.4R3-S8; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3.

Published

Embed this verdict
TruePositive verdict for CVE-2023-36846
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2023-36846/badge.svg)](https://www.truepositive.app/cve/CVE-2023-36846)
HTML
<a href="https://www.truepositive.app/cve/CVE-2023-36846"><img src="https://www.truepositive.app/cve/CVE-2023-36846/badge.svg" alt="TruePositive verdict for CVE-2023-36846"></a>

Live badge — updates automatically as the community verdict changes.

Community ground truth

Community verdict

3 verdicts
Not a real issue

to add your verdict.

Community real-world severity: High (High 3) — CVSS base score 5.3

Practitioners rate this higher than its CVSS — treat with extra caution.

Field notes & remediation

Verdicts are the quick signal — notes are the evidence and fixes behind them.

No notes yet — be the first to share what you saw or a fix that worked.

    Same weaknessCWE-306 · Missing Authentication for Critical Function.