Evidence dossier

CVE-2023-36851

Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files

Exploited in the wild (CISA KEV since Nov 13, 2023). NVD reports CVSS 3.1 5.3. EPSS estimates 1.1% exploit likelihood as of Aug 27, 2026.

58.059.5Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload and download arbitrary files via J-Web, leading to a loss of integrity or confidentiality, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * 21.2 versions prior to 21.2R3-S8; * 21.4 versions prior to 21.4R3-S6; * 22.1 versions prior to 22.1R3-S5; * 22.2 versions prior to 22.2R3-S3; * 22.3 versions prior to 22.3R3-S2; * 22.4 versions prior to 22,4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S2, 23.2R2.

State
PUBLISHED
Published
Sep 26, 2023
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    juniper

    Record text: Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files

    Inspect raw assertion
    Field
    container
    Value
    Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 1.09% probability · 62.96th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.010910000000; percentile 0.629610000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Nov 13, 2023 · first observed Jul 19, 2026

Exploit likelihood1.09%

FIRST EPSS · score date Aug 27, 2026 · 63th percentile · first observed Aug 27, 2026

SeverityCVSS 5.3

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
juniperOriginal assertion
Record text

Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files

Inspect raw assertion
Field
container
Value
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

1.09% probability · 62.96th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.010910000000; percentile 0.629610000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
153Underlying assertions
92Canonical products
62Target assertions
91Constraint assertions

Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

93 scope groups

juniper · source assertedJuniper NetworksJunos OSDirect source scope
Affected: 21.2 to before 21.2R3-S8 (semver comparison)Affected: 21.4 to before 21.4R3-S6 (semver comparison)Affected: 22.1 to before 22.1R3-S5 (semver comparison)Affected: 22.2 to before 22.2R3-S3 (semver comparison)Affected: 22.3 to before 22.3R3-S2 (semver comparison)Affected: 22.4 to before 22.4R2-S2, 22.4R3 (semver comparison)Affected: 23.2 to before 23.2R1-S2, 23.2R2 (semver comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "21.2", "lessThan": "21.2R3-S8", "versionType": "semver"}, {"status": "affected", "version": "21.4", "lessThan": "21.4R3-S6", "versionType": "semver"}, {"status": "affected", "version": "22.1", "lessThan": "22.1R3-S5", "versionType": "semver"}, {"status": "affected", "version": "22.2", "lessThan": "22.2R3-S3", "versionType": "semver"}, {"status": "affected", "version": "22.3", "lessThan": "22.3R3-S2", "versionType": "semver"}, {"status": "affected", "version": "22.4", "lessThan": "22.4R2-S2, 22.4R3", "versionType": "semver"}, {"status": "affected", "version": "23.2", "lessThan": "23.2R1-S2, 23.2R2", "versionType": "semver"}]
NVD CPE · HARDWAREjuniperex2200Environmental constraint · 1 assertions
Version not applicableCanonical identity product-c74392df4887de607ea63ec2a1359df06d7f576f2f48e82f211148d473e263f0Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex2200:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ae3d4f71-8476-4f0d-a976-a308d6483d6d
NVD CPE · HARDWAREjuniperex2200-cEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-7a8ad787e5a98b6a86f3d1d0b92692979e3f15555a984c2c6a19fe303f55d565Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex2200-c:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f7bd5636-93d5-4c06-964f-00055df6b2b8
NVD CPE · HARDWAREjuniperex2200-vcEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-222b3061e728a78053905caf9484afcda1aaeffd1cbc29fc7dfbe492f880f41eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex2200-vc:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d066a90d-f7f2-4ea5-8f0c-d0e189ddb05d
NVD CPE · HARDWAREjuniperex2300Environmental constraint · 1 assertions
Version not applicableCanonical identity product-6b2f3e8b90b79725c18446c56defb4811ec4345d40a3046f0cebcc44d3af6991Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex2300:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3b3302cb-457f-4bd2-b80b-f70fb4c4542e
NVD CPE · HARDWAREjuniperex2300-24mpEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-3fa78f1d8704ffa256936c666af7a6f80e8b17b77fa7237a59f51bdac4391641Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex2300-24mp:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b3a0d9c0-34d3-430f-abfa-b68010a8825d
NVD CPE · HARDWAREjuniperex2300-24pEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-aae7fe243bcab688fbbc960944716f7fcf35dcef93e0230d2ac1dfb7e28a47bcLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex2300-24p:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5e04b126-f290-4242-bb80-5f573d623e6e
NVD CPE · HARDWAREjuniperex2300-24tEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-1fc636937fd0b5357c78d3169868c5a1528971ea4da9b5b4168f026735309331Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex2300-24t:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    671d9977-7657-48c7-a07c-4aed54380a86
NVD CPE · HARDWAREjuniperex2300-48mpEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-16aa3e7f8a714e0fb6915ca7f2930baf616298686c8f2d4c5953d19c25eb9143Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex2300-48mp:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0e100c3c-070d-4132-927f-756538b91491
NVD CPE · HARDWAREjuniperex2300-48pEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-7b86de7888df362cfa4378af6e249d5a9cf808d021412bc82c5829fe658712cfLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex2300-48p:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2032e7dd-96fd-48b7-922c-5fe04675796c
NVD CPE · HARDWAREjuniperex2300-48tEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-cdc2adc344d068c203237176621ded0a21bd5f3b407e8abd3a1ea3379e4ae14aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex2300-48t:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2d907d6a-b7c4-4a10-aa58-0f908575a435
NVD CPE · HARDWAREjuniperex2300-cEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-f066083d632d0f1a9c6f96271242480a4142437ab9973cbcfcad3cae71751e36Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex2300-c:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    979c3597-c53b-4f4b-9ea7-126da036c86d
NVD CPE · HARDWAREjuniperex2300mEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-5ad515eca29c1f5b0351cef49c589986a6518a96c17e567e6ceaad237cbe955eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex2300m:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    62a536da-5a57-4255-ab22-f99f8b7ff62a
NVD CPE · HARDWAREjuniperex3200Environmental constraint · 1 assertions
Version not applicableCanonical identity product-7422d5a52ebcb7e88a13ab18d11ce47fa6c3be8fb5b011849869e070bf135c55Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex3200:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4c7a20fc-a19f-4881-a0e8-c440e9fe60d0
NVD CPE · HARDWAREjuniperex3300Environmental constraint · 1 assertions
Version not applicableCanonical identity product-1abfca3a6c274874713a26146820769dbceb4a2ba834283ad64d3a7fcef6ed9dLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex3300:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fc326549-217d-4194-8310-ab398d6ff3f0
NVD CPE · HARDWAREjuniperex3300-vcEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-b3ce8261e3b249b2135dad8060acc9699913268c6857e76d06705924be1d82d0Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex3300-vc:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d32b9b26-8bf0-4c56-a9bf-d9bbaea50506
NVD CPE · HARDWAREjuniperex3400Environmental constraint · 1 assertions
Version not applicableCanonical identity product-7f03639aeb9ee1b3dfd792746a30ed7c82130975cd3f401beed2fc2ec0b5ee7fLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex3400:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    47daf5e7-e610-4d74-8573-41c16d642837
NVD CPE · HARDWAREjuniperex4200Environmental constraint · 1 assertions
Version not applicableCanonical identity product-8afb7d0ce341d34731eefae6cfa3ca932750260e09b54ca0e3b508bff06a2739Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex4200:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    53269c69-3d1e-4f05-8ef6-81743d7a699e
NVD CPE · HARDWAREjuniperex4200-vcEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-ff38da15b8d14212575af8f64cbe6c772d6dbe8f9fed72d61bbc6485c75a9b63Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex4200-vc:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e0f54adf-7c13-4aa6-b61e-627d4dbb1cf3
NVD CPE · HARDWAREjuniperex4300Environmental constraint · 1 assertions
Version not applicableCanonical identity product-0db9202cb4aada050637475daed594d48ffbea72908d2ee719b1e3f1b5e25c46Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex4300:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e594d6dc-87f6-40d2-8268-ed6021462168
NVD CPE · HARDWAREjuniperex4300-24pEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-84dd25d53466195810943ae6223adbb6f9a7d82c13e895f288722ff83e4980f1Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex4300-24p:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7bea4bc3-093f-4de6-bed1-2c7d2fc2c8a5
NVD CPE · HARDWAREjuniperex4300-24p-sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-68d8c27c0eb42592eb31db18b9e26d2c05f3d910df9937c2bb16e947c0328359Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex4300-24p-s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    592377cc-4044-4fdd-a3df-cbf25754ee4d
NVD CPE · HARDWAREjuniperex4300-24tEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-c4ff90cbc679140327f46aeae24b7eccdc3bc4865ef1a7ce639ff54273776a69Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex4300-24t:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d12e8275-ef6b-44f9-a7d8-a769cdb5eed5
NVD CPE · HARDWAREjuniperex4300-24t-sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-6152a07d6aff2d98c7fb2c8e66e0375e4a28a75e3b920cef7d35b1185ad895c6Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex4300-24t-s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d3e63215-246e-49f3-a537-8a90d512dab0
NVD CPE · HARDWAREjuniperex4300-32fEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-60e399600b00f97a1afce6c7715cc91ec4f94708def0d17047f52e5710ff29f3Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:juniper:ex4300-32f:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ad1a5e69-928a-41a0-8b9b-91f307d99854

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

5.3
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
5.3
sirt@juniper.netCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
5.3
juniperCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.