cbcvebase.
CVE-2022-22239
published 2022-10-18

CVE-2022-22239: An Execution with Unnecessary Privileges vulnerability in Management Daemon (mgd) of Juniper Networks Junos OS Evolved allows a locally authenticated attacker…

PriorityP347high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.18%
7.2th percentile
An Execution with Unnecessary Privileges vulnerability in Management Daemon (mgd) of Juniper Networks Junos OS Evolved allows a locally authenticated attacker with low privileges to escalate their privileges on the device and potentially remote systems. This vulnerability allows a locally authenticated attacker with access to the ssh operational command to escalate their privileges on the system to root, or if there is user interaction on the local device to potentially escalate privileges on a remote system to root. This issue affects Juniper Networks Junos OS Evolved: All versions prior to 20.4R3-S5-EVO; 21.1-EVO versions prior to 21.1R3-EVO; 21.2-EVO versions prior to 21.2R2-S1-EVO, 21.2R3-EVO; 21.3-EVO versions prior to 21.3R2-EVO. This issue does not affect Juniper Networks Junos OS.

Affected

10 ranges
VendorProductVersion rangeFixed in
juniperjunos_os
juniperjunos_os_evolved< 20.420.4
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniper_networksjunos_os_evolved>= 21.1-EVO < 21.1R3-EVO21.1R3-EVO
juniper_networksjunos_os_evolved>= 21.2-EVO < 21.2R2-S1-EVO, 21.2R3-EVO21.2R2-S1-EVO, 21.2R3-EVO
juniper_networksjunos_os_evolved>= 21.3-EVO < 21.3R2-EVO21.3R2-EVO
juniper_networksjunos_os_evolved>= unspecified < 20.4R3-S5-EVO20.4R3-S5-EVO
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.