CVE-2022-22241
published 2022-10-18CVE-2022-22241: An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.13%
62.9th percentile
An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without proper authorization. Utilizing a crafted POST request, deserialization may occur which could lead to unauthorized local file access or the ability to execute arbitrary commands. This issue affects Juniper Networks Junos OS: all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S9; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R2-S2, 21.3R3; 21.4 versions prior to 21.4R1-S2, 21.4R2-S1, 21.4R3; 22.1 versions prior to 22.1R1-S1, 22.1R2.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | j-web | — | — |
| juniper | junos | < 19.1 | 19.1 |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper_networks | junos_os | >= 19.2 < 19.2R3-S6 | 19.2R3-S6 |
| juniper_networks | junos_os | >= 19.3 < 19.3R3-S7 | 19.3R3-S7 |
| juniper_networks | junos_os | >= 19.4 < 19.4R2-S7, 19.4R3-S9 | 19.4R2-S7, 19.4R3-S9 |
| juniper_networks | junos_os | >= 20.1 < 20.1R3-S5 | 20.1R3-S5 |
| juniper_networks | junos_os | >= 20.2 < 20.2R3-S5 | 20.2R3-S5 |
| juniper_networks | junos_os | >= 20.3 < 20.3R3-S5 | 20.3R3-S5 |
| juniper_networks | junos_os | >= 20.4 < 20.4R3-S4 | 20.4R3-S4 |
| juniper_networks | junos_os | >= 21.1 < 21.1R3-S2 | 21.1R3-S2 |
| juniper_networks | junos_os | >= 21.2 < 21.2R3-S1 | 21.2R3-S1 |
Detection & IOCsextracted from sources · hover to see the quote
path/jsdm/ajax/logging_browse.php
commandfilepath=phar:
snort
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Potential Juniper Phar Deserialization RCE Attempt (CVE-2022-22241)"; flow:established,to_server; http.request_line; content:"POST|20|/jsdm/ajax/logging_browse.php|20|"; startswith; fast_pattern; http.request_body; content:"filepath|3d|phar|3a|"; reference:url,octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/; reference:cve,2022-22241; classtype:trojan-activity; sid:2039591; rev:1; metadata:attack_target Networking_Equipment, created_at 2022_10_28, cve CVE_2022_22241, deployment Perimeter, deployment SSLDecrypt, performance_impact Low, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_10_28;)
- →Look for unauthenticated POST requests to /jsdm/ajax/logging_browse.php on J-Web (HTTP) containing a 'filepath' parameter with a phar:// URI scheme, which indicates a PHP phar deserialization exploitation attempt.
- →The attack vector is a crafted POST request to the J-Web component; deserialization of the phar:// payload may lead to unauthorized local file access or arbitrary command execution without authentication.
- →Deploy the Snort/Suricata rule at the network perimeter (or with SSL decryption enabled) targeting inbound HTTP traffic to networking equipment; the rule carries high confidence and major severity classification.
- ·The Snort rule targets HTTP traffic; if J-Web is served over HTTPS, SSL/TLS inspection (SSLDecrypt) must be enabled on the monitoring sensor for the rule to fire.
- ·The vulnerability affects unauthenticated attackers, meaning no session cookie or credential is required — perimeter controls should not assume prior authentication as a filter.
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f22c-xfcp-g8p7: An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data wi
ghsa_unreviewed·2022-10-18
CVE-2022-22241 [HIGH] CWE-502 GHSA-f22c-xfcp-g8p7: An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data wi
An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without proper authorization. Utilizing a crafted POST request, deserialization may occur which could lead to unauthorized local file access or the ability to execute arbitrary commands. This issue affects Juniper Networks Junos OS: all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S9; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R2-S2, 21.3R3; 21.4 versions prior to 21.4
Juniper
CVE-2022-22241: An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data wi
vendor_juniper·2022-10-18·CVSS 8.1
CVE-2022-22241 [HIGH] CWE-20 CVE-2022-22241: An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data wi
CVE-2022-22241: An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without proper authorization. Utilizing a crafted POST request, deserialization may occur which could lead to unauthorized local file access or the ability to execute arbitrary commands. This issue affects Juniper Networks Junos OS: all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S9; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R2-S2, 21.3R3; 21.4 versio
Suricata
ET MALWARE Potential Juniper Phar Deserialization RCE Attempt (CVE-2022-22241)
suricata·2022-10-28·CVSS 8.1
CVE-2022-22241 [HIGH] ET MALWARE Potential Juniper Phar Deserialization RCE Attempt (CVE-2022-22241)
ET MALWARE Potential Juniper Phar Deserialization RCE Attempt (CVE-2022-22241)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Potential Juniper Phar Deserialization RCE Attempt (CVE-2022-22241)"; flow:established,to_server; http.request_line; content:"POST|20|/jsdm/ajax/logging_browse.php|20|"; startswith; fast_pattern; http.request_body; content:"filepath|3d|phar|3a|"; reference:url,octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/; reference:cve,2022-22241; classtype:trojan-activity; sid:2039591; rev:1; metadata:attack_target Networking_Equipment, created_at 2022_10_28, cve CVE_2022_22241, deployment Perimeter, deployment SSLDecrypt, performance_impact Low, confidence High, signature_severity Major, tag Description_Generated_By_Proo
No public exploits indexed.
No writeups or analysis indexed.
2022-10-18
Published