7.8
CVSSv3

CVE-2022-22221

Published: 20/07/2022 Updated: 29/07/2022
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An Improper Neutralization of Special Elements vulnerability in the download manager of Juniper Networks Junos OS on SRX Series and EX Series allows a locally authenticated attacker with low privileges to take full control over the device. One aspect of this vulnerability is that the attacker needs to be able to execute any of the "request ..." or "show system download ..." commands. This issue affects Juniper Networks Junos OS on SRX Series and EX Series: All versions before 19.2R1-S9, 19.2R3-S5; 19.3 versions before 19.3R3-S6; 19.4 versions before 19.4R3-S8; 20.1 versions before 20.1R3-S4; 20.2 versions before 20.2R3-S4; 20.3 versions before 20.3R3-S3; 20.4 versions before 20.4R3-S2, 20.4R3-S3; 21.1 versions before 21.1R3-S1; 21.2 versions before 21.2R2-S2, 21.2R3; 21.3 versions before 21.3R2, 21.3R3; 21.4 versions before 21.4R1-S1, 21.4R2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

juniper junos 19.2

juniper junos 19.3

juniper junos 19.4

juniper junos

juniper junos 20.1

juniper junos 20.2

juniper junos 20.3

juniper junos 20.4

juniper junos 21.1

juniper junos 21.2

juniper junos 21.3

juniper junos 21.4

Recent Articles

CISA pulls the fire alarm on Juniper Networks bugs
The Register • Jessica Lyons Hardcastle • 01 Jan 1970

Topics Security Off-Prem On-Prem Software Offbeat Vendor Voice Vendor Voice Resources Hate to ruin your Friday What do you want The Register to do for you?

Juniper Networks has patched critical-rated bugs across its Junos Space, Contrail Networking and NorthStar Controller products that are serious enough to prompt CISA to weigh in and advise admins to update the software as soon as possible. "CISA encourages users and administrators to review the Juniper Networks security advisories page and apply the necessary updates," according to the Feds' warning this week. Key thing here is review: some of these flaws can be exploited to bring down equipme...