CVE-2022-22221
Last modified
CVE-2022-22221 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An Improper Neutralization of Special Elements vulnerability in the download manager of Juniper Networks Junos OS on SRX Series and EX Series allows a locally authenticated attacker with low privileges to take full control over the device. One aspect of this vulnerability is that the attacker needs to be able to execute any of the "request ..." or "show system download ..." commands. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
An Improper Neutralization of Special Elements vulnerability in the download manager of Juniper Networks Junos OS on SRX Series and EX Series allows a locally authenticated attacker with low privileges to take full control over the device. One aspect of this vulnerability is that the attacker needs to be able to execute any of the "request ..." or "show system download ..." commands. This issue affects Juniper Networks Junos OS on SRX Series and EX Series: All versions prior to 19.2R1-S9, 19.2R3-S5; 19.3 versions prior to 19.3R3-S6; 19.4 versions prior to 19.4R3-S8; 20.1 versions prior to 20.1R3-S4; 20.2 versions prior to 20.2R3-S4; 20.3 versions prior to 20.3R3-S3; 20.4 versions prior to 20.4R3-S2, 20.4R3-S3; 21.1 versions prior to 21.1R3-S1; 21.2 versions prior to 21.2R2-S2, 21.2R3; 21.3 versions prior to 21.3R2, 21.3R3; 21.4 versions prior to 21.4R1-S1, 21.4R2.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | < 19.2 | — |
| Juniper | Junos | 19.2 | — |
| Juniper | Junos | 19.3 | — |
| Juniper | Junos | 19.4 | — |
| Juniper | Junos | 20.1 | — |
| Juniper | Junos | 20.2 | — |
| Juniper | Junos | 20.3 | — |
| Juniper | Junos | 20.4 | — |
| Juniper | Junos | 21.1 | — |
| Juniper | Junos | 21.2 | — |
| Juniper | Junos | 21.3 | R1 |
| Juniper | Junos | 21.4 | R1 |
References
- https://kb.juniper.net/JSA69725Vendor Advisory
- https://kb.juniper.net/JSA69725Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-22221?
How severe is CVE-2022-22221?
How do I fix CVE-2022-22221?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-22216An Exposure of Sensitive Information to an Unauthorized Acto…4.3
- CVE-2022-22217An Improper Check for Unusual or Exceptional Conditions vuln…6.5
- CVE-2022-22218On SRX Series devices, an Improper Check for Unusual or Exce…7.5
- CVE-2022-22219Due to the Improper Handling of an Unexpected Data Type in t…5.9
- CVE-2022-2222The Download Monitor WordPress plugin before 4.5.91 does not…4.9
- CVE-2022-22220A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerab…5.9
- CVE-2022-22223On QFX10000 Series devices using Juniper Networks Junos OS w…7.5
- CVE-2022-22224An Improper Check or Handling of Exceptional Conditions vuln…6.5
- CVE-2022-22225A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerab…5.9
- CVE-2022-22226In VxLAN scenarios on EX4300-MP, EX4600, QFX5000 Series devi…6.5
- CVE-2022-22227An Improper Check for Unusual or Exceptional Conditions vuln…5.3
- CVE-2022-22228An Improper Validation of Specified Type of Input vulnerabil…7.5
Are you affected by CVE-2022-22221?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
