cbcvebase.
CVE-2022-22241
published 2022-10-18

CVE-2022-22241: An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without…

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.13%
62.9th percentile
An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without proper authorization. Utilizing a crafted POST request, deserialization may occur which could lead to unauthorized local file access or the ability to execute arbitrary commands. This issue affects Juniper Networks Junos OS: all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S9; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R2-S2, 21.3R3; 21.4 versions prior to 21.4R1-S2, 21.4R2-S1, 21.4R3; 22.1 versions prior to 22.1R1-S1, 22.1R2.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
juniperj-web
juniperjunos< 19.119.1
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos_os
juniper_networksjunos_os>= 19.2 < 19.2R3-S619.2R3-S6
juniper_networksjunos_os>= 19.3 < 19.3R3-S719.3R3-S7
juniper_networksjunos_os>= 19.4 < 19.4R2-S7, 19.4R3-S919.4R2-S7, 19.4R3-S9
juniper_networksjunos_os>= 20.1 < 20.1R3-S520.1R3-S5
juniper_networksjunos_os>= 20.2 < 20.2R3-S520.2R3-S5
juniper_networksjunos_os>= 20.3 < 20.3R3-S520.3R3-S5
juniper_networksjunos_os>= 20.4 < 20.4R3-S420.4R3-S4
juniper_networksjunos_os>= 21.1 < 21.1R3-S221.1R3-S2
juniper_networksjunos_os>= 21.2 < 21.2R3-S121.2R3-S1

Detection & IOCsextracted from sources · hover to see the quote

path/jsdm/ajax/logging_browse.php
commandfilepath=phar:
snort
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Potential Juniper Phar Deserialization RCE Attempt (CVE-2022-22241)"; flow:established,to_server; http.request_line; content:"POST|20|/jsdm/ajax/logging_browse.php|20|"; startswith; fast_pattern; http.request_body; content:"filepath|3d|phar|3a|"; reference:url,octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/; reference:cve,2022-22241; classtype:trojan-activity; sid:2039591; rev:1; metadata:attack_target Networking_Equipment, created_at 2022_10_28, cve CVE_2022_22241, deployment Perimeter, deployment SSLDecrypt, performance_impact Low, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_10_28;)
  • Look for unauthenticated POST requests to /jsdm/ajax/logging_browse.php on J-Web (HTTP) containing a 'filepath' parameter with a phar:// URI scheme, which indicates a PHP phar deserialization exploitation attempt.
  • The attack vector is a crafted POST request to the J-Web component; deserialization of the phar:// payload may lead to unauthorized local file access or arbitrary command execution without authentication.
  • Deploy the Snort/Suricata rule at the network perimeter (or with SSL decryption enabled) targeting inbound HTTP traffic to networking equipment; the rule carries high confidence and major severity classification.
  • ·The Snort rule targets HTTP traffic; if J-Web is served over HTTPS, SSL/TLS inspection (SSLDecrypt) must be enabled on the monitoring sensor for the rule to fire.
  • ·The vulnerability affects unauthenticated attackers, meaning no session cookie or credential is required — perimeter controls should not assume prior authentication as a filter.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.