Attackers targeted multiple Juniper Networks Junos OS flaws affecting SRX and EX devices, focusing on the J-Web interface and chaining vulnerabilities including CVE-2023-36845, CVE-2023-36846, CVE-2023-36847, and CVE-2023-36851 to achieve unauthenticated remote code execution. Security monitoring observed exploitation activity beginning on 2023-09-13 after the vulnerabilities were disclosed, with the issue affecting internet-exposed network infrastructure.
One observed exploit attempt specifically targeted CVE-2023-36845 and used a crafted POST request with PHPRC and auto_prepend_file parameters to try to access /etc/passwd, indicating active probing for code execution and file disclosure on vulnerable systems. Most detected source traffic was attributed to Malaysia, with a smaller share linked to the United States, and defenders were urged to update affected Junos OS versions immediately to reduce exposure.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC reported detecting attack activity targeting the Juniper Junos OS vulnerabilities beginning on 2023-09-13. The attacks targeted affected SRX and EX devices, particularly via the J-Web interface.
Among the detected activity, MBSD-SOC observed an exploit attempt for CVE-2023-36845 that tried to access /etc/passwd. The payload used a crafted POST request with PHPRC=/dev/fd/0 and auto_prepend_file set to /etc/passwd.
The MBSD report states that CVE-2023-36851 was additionally published in September 2023 as part of the Junos OS vulnerability set being exploited. It was referenced alongside CVE-2023-36844, CVE-2023-36845, CVE-2023-36846, and CVE-2023-36847.
In August 2023, multiple Juniper Networks Junos OS vulnerabilities affecting SRX and EX series devices were publicly disclosed in an out-of-cycle security bulletin. The flaws could be chained through the J-Web interface to enable unauthenticated remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.