CISA KEV · catalog date Nov 13, 2023 · first observed Jul 19, 2026
Evidence dossier
CVE-2023-36847
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Exploited in the wild (CISA KEV since Nov 13, 2023). NVD reports CVSS 3.1 5.3. EPSS estimates 85.8% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S8; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S4; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S1; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3.
- State
- PUBLISHED
- Published
- Aug 17, 2023
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAjuniperOriginal evidence ↗
Record text: Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Inspect raw assertion
- Field
container- Value
- Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 85.77% probability · 99.71th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.857690000000; percentile 0.997100000000
FIRST EPSS · score date Aug 26, 2026 · 99.7th percentile · first observed Aug 26, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Inspect raw assertion
- Field
container- Value
- Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability
85.77% probability · 99.71th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.857690000000; percentile 0.997100000000
Applicability
Cited product scope
Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
65 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "lessThan": "20.4R3-S8", "versionType": "semver"}, {"status": "affected", "version": "21.1", "lessThan": "21.1*", "versionType": "semver"}, {"status": "affected", "version": "21.2", "lessThan": "21.2R3-S6", "versionType": "semver"}, {"status": "affected", "version": "21.3", "lessThan": "21.3R3-S5", "versionType": "semver"}, {"status": "affected", "version": "21.4", "lessThan": "21.4R3-S4", "versionType": "semver"}, {"status": "affected", "version": "22.1", "lessThan": "22.1R3-S3", "versionType": "semver"}, {"status": "affected", "version": "22.2", "lessThan": "22.2R3-S1", "versionType": "semver"}, {"status": "affected", "version": "22.3", "lessThan": "22.3R2-S2, 22.3R3", "versionType": "semver"}, {"status": "affected", "version": "22.4", "lessThan": "22.4R2-S1, 22.4R3", "versionType": "semver"}]product-c74392df4887de607ea63ec2a1359df06d7f576f2f48e82f211148d473e263f0Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex2200:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ae3d4f71-8476-4f0d-a976-a308d6483d6d
product-7a8ad787e5a98b6a86f3d1d0b92692979e3f15555a984c2c6a19fe303f55d565Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex2200-c:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f7bd5636-93d5-4c06-964f-00055df6b2b8
product-222b3061e728a78053905caf9484afcda1aaeffd1cbc29fc7dfbe492f880f41eLinked exactInspect raw assertion
cpe:2.3:h:juniper:ex2200-vc:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d066a90d-f7f2-4ea5-8f0c-d0e189ddb05d
product-6b2f3e8b90b79725c18446c56defb4811ec4345d40a3046f0cebcc44d3af6991Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex2300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3b3302cb-457f-4bd2-b80b-f70fb4c4542e
product-3fa78f1d8704ffa256936c666af7a6f80e8b17b77fa7237a59f51bdac4391641Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex2300-24mp:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b3a0d9c0-34d3-430f-abfa-b68010a8825d
product-aae7fe243bcab688fbbc960944716f7fcf35dcef93e0230d2ac1dfb7e28a47bcLinked exactInspect raw assertion
cpe:2.3:h:juniper:ex2300-24p:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5e04b126-f290-4242-bb80-5f573d623e6e
product-1fc636937fd0b5357c78d3169868c5a1528971ea4da9b5b4168f026735309331Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex2300-24t:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
671d9977-7657-48c7-a07c-4aed54380a86
product-16aa3e7f8a714e0fb6915ca7f2930baf616298686c8f2d4c5953d19c25eb9143Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex2300-48mp:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0e100c3c-070d-4132-927f-756538b91491
product-7b86de7888df362cfa4378af6e249d5a9cf808d021412bc82c5829fe658712cfLinked exactInspect raw assertion
cpe:2.3:h:juniper:ex2300-48p:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2032e7dd-96fd-48b7-922c-5fe04675796c
product-cdc2adc344d068c203237176621ded0a21bd5f3b407e8abd3a1ea3379e4ae14aLinked exactInspect raw assertion
cpe:2.3:h:juniper:ex2300-48t:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2d907d6a-b7c4-4a10-aa58-0f908575a435
product-f066083d632d0f1a9c6f96271242480a4142437ab9973cbcfcad3cae71751e36Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex2300-c:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
979c3597-c53b-4f4b-9ea7-126da036c86d
product-5ad515eca29c1f5b0351cef49c589986a6518a96c17e567e6ceaad237cbe955eLinked exactInspect raw assertion
cpe:2.3:h:juniper:ex2300m:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
62a536da-5a57-4255-ab22-f99f8b7ff62a
product-7422d5a52ebcb7e88a13ab18d11ce47fa6c3be8fb5b011849869e070bf135c55Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex3200:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4c7a20fc-a19f-4881-a0e8-c440e9fe60d0
product-1abfca3a6c274874713a26146820769dbceb4a2ba834283ad64d3a7fcef6ed9dLinked exactInspect raw assertion
cpe:2.3:h:juniper:ex3300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fc326549-217d-4194-8310-ab398d6ff3f0
product-b3ce8261e3b249b2135dad8060acc9699913268c6857e76d06705924be1d82d0Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex3300-vc:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d32b9b26-8bf0-4c56-a9bf-d9bbaea50506
product-7f03639aeb9ee1b3dfd792746a30ed7c82130975cd3f401beed2fc2ec0b5ee7fLinked exactInspect raw assertion
cpe:2.3:h:juniper:ex3400:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
47daf5e7-e610-4d74-8573-41c16d642837
product-8afb7d0ce341d34731eefae6cfa3ca932750260e09b54ca0e3b508bff06a2739Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex4200:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
53269c69-3d1e-4f05-8ef6-81743d7a699e
product-ff38da15b8d14212575af8f64cbe6c772d6dbe8f9fed72d61bbc6485c75a9b63Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex4200-vc:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e0f54adf-7c13-4aa6-b61e-627d4dbb1cf3
product-0db9202cb4aada050637475daed594d48ffbea72908d2ee719b1e3f1b5e25c46Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex4300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e594d6dc-87f6-40d2-8268-ed6021462168
product-84dd25d53466195810943ae6223adbb6f9a7d82c13e895f288722ff83e4980f1Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex4300-24p:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7bea4bc3-093f-4de6-bed1-2c7d2fc2c8a5
product-68d8c27c0eb42592eb31db18b9e26d2c05f3d910df9937c2bb16e947c0328359Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex4300-24p-s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
592377cc-4044-4fdd-a3df-cbf25754ee4d
product-c4ff90cbc679140327f46aeae24b7eccdc3bc4865ef1a7ce639ff54273776a69Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex4300-24t:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d12e8275-ef6b-44f9-a7d8-a769cdb5eed5
product-6152a07d6aff2d98c7fb2c8e66e0375e4a28a75e3b920cef7d35b1185ad895c6Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex4300-24t-s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d3e63215-246e-49f3-a537-8a90d512dab0
product-60e399600b00f97a1afce6c7715cc91ec4f94708def0d17047f52e5710ff29f3Linked exactInspect raw assertion
cpe:2.3:h:juniper:ex4300-32f:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ad1a5e69-928a-41a0-8b9b-91f307d99854
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.