VYPR
High severity7.8NVD Advisory· Published Oct 18, 2022· Updated Jun 17, 2026

CVE-2022-22251

CVE-2022-22251

Description

On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker to elevate their permissions to take control of any instance of a cSRX software deployment. This issue affects Juniper Networks Junos OS 20.2 version 20.2R1 and later versions prior to 21.2R1 on cSRX Series.

Affected products

4
  • cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*range: >=20.2,<21.2
    • (no CPE)range: 20.2R1 <= versions < 21.2R1
    • (no CPE)range: 20.2R1
  • Range: 20.2R1 <= versions < 21.2R1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.