« Volver al listado

CVE-2022-22251

Estado: ModificadaAlta (7.8)—

On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker to elevate their permissions to take control of any instance of a cSRX software deployment. This issue affects Juniper Networks Junos OS 20.2 version 20.2R1 and later versions prior to 21.2R1 on cSRX Series.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-22251",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-22251",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-08T19:26:16.282945Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "sirt@juniper.net",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "sirt@juniper.net",
      "affectedData": [
        {
          "vendor": "Juniper Networks",
          "product": "Junos OS",
          "versions": [
            {
              "status": "unaffected",
              "version": "unspecified",
              "lessThan": "20.2R1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "20.2R1",
              "lessThan": "20.2*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "20.3R1",
              "lessThan": "20.3*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "20.4R1",
              "lessThan": "20.4*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "21.1R1",
              "lessThan": "21.1*",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "cSRX Series"
          ]
        }
      ]
    }
  ],
  "published": "2022-10-18T03:15:11.657",
  "references": [
    {
      "url": "https://kb.juniper.net/JSA69908",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "sirt@juniper.net"
    },
    {
      "url": "https://kb.juniper.net/JSA69908",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "sirt@juniper.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-257"
        },
        {
          "lang": "en",
          "value": "CWE-275"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker to elevate their permissions to take control of any instance of a cSRX software deployment. This issue affects Juniper Networks Junos OS 20.2 version 20.2R1 and later versions prior to 21.2R1 on cSRX Series."
    },
    {
      "lang": "es",
      "value": "En los dispositivos cSRX Series, los problemas de permisos de software en el sistema de archivos del contenedor y los archivos almacenados, combinados con el almacenamiento de contraseñas en un formato recuperable en Junos OS de Juniper Networks, permiten a un atacante local poco privilegiado elevar sus permisos para tomar el control de cualquier instancia de una implementación de software cSRX. Este problema afecta a Juniper Networks Junos OS 20.2 versión 20.2R1 y versiones posteriores anteriores a 21.2R1 en cSRX Series"
    }
  ],
  "lastModified": "2026-06-17T04:28:06.760",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F706555A-8840-4EC4-ABCC-5EE92EDA050D",
              "versionEndExcluding": "21.2",
              "versionStartIncluding": "20.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:juniper:csrx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "11D4A86D-BDB4-4A01-96FE-7E023C58074B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "sirt@juniper.net"
}