PT-2022-5204 · Juniper Networks · Junos
Published
2022-10-12
·
Updated
2022-10-21
·
CVE-2022-22251
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS versions 20.2R1 through 21.2R1 on cSRX Series
Description
The issue is related to software permission problems in the container filesystem and stored files, combined with the storage of passwords in a recoverable format in Juniper Networks Junos OS. This allows a local, low-privileged attacker to elevate their permissions and take control of any instance of a cSRX software deployment.
Recommendations
For versions 20.2R1 through 21.2R1, update to version 21.2R1 or later to resolve the issue.
At the moment, there is no information about additional mitigation measures for this vulnerability.
Fix
Incorrect Default Permissions
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Junos