PT-2022-5204 · Juniper Networks · Junos

Published

2022-10-12

·

Updated

2022-10-21

·

CVE-2022-22251

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS versions 20.2R1 through 21.2R1 on cSRX Series
Description The issue is related to software permission problems in the container filesystem and stored files, combined with the storage of passwords in a recoverable format in Juniper Networks Junos OS. This allows a local, low-privileged attacker to elevate their permissions and take control of any instance of a cSRX software deployment.
Recommendations For versions 20.2R1 through 21.2R1, update to version 21.2R1 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Fix

Incorrect Default Permissions

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2022-06461
CVE-2022-22251

Affected Products

Junos