High severity7.8NVD Advisory· Published Oct 18, 2022· Updated Jun 17, 2026
CVE-2022-22251
CVE-2022-22251
Description
On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker to elevate their permissions to take control of any instance of a cSRX software deployment. This issue affects Juniper Networks Junos OS 20.2 version 20.2R1 and later versions prior to 21.2R1 on cSRX Series.
Affected products
4cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*range: >=20.2,<21.2
- (no CPE)range: 20.2R1 <= versions < 21.2R1
- (no CPE)range: 20.2R1
- Range: 20.2R1 <= versions < 21.2R1
Patches
Vulnerability mechanics
References
1- kb.juniper.net/JSA69908nvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.