CVE-2022-22245
published 2022-10-18CVE-2022-22245: A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the device by…
PriorityP427medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.62%
45.6th percentile
A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the device by bypassing validation checks built into Junos OS. The attacker should not be able to execute the file due to validation checks built into Junos OS. Successful exploitation of this vulnerability could lead to loss of filesystem integrity. This issue affects Juniper Networks Junos OS: all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R3-S9; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R2-S2, 21.3R3; 21.4 versions prior to 21.4R1-S2, 21.4R2-S1, 21.4R3; 22.1 versions prior to 22.1R1-S1, 22.1R2.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | j-web | — | — |
| juniper | junos | < 19.1 | 19.1 |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper_networks | junos_os | >= 19.2 < 19.2R3-S6 | 19.2R3-S6 |
| juniper_networks | junos_os | >= 19.3 < 19.3R3-S7 | 19.3R3-S7 |
| juniper_networks | junos_os | >= 19.4 < 19.4R3-S9 | 19.4R3-S9 |
| juniper_networks | junos_os | >= 20.1 < 20.1R3-S5 | 20.1R3-S5 |
| juniper_networks | junos_os | >= 20.2 < 20.2R3-S5 | 20.2R3-S5 |
| juniper_networks | junos_os | >= 20.3 < 20.3R3-S5 | 20.3R3-S5 |
| juniper_networks | junos_os | >= 20.4 < 20.4R3-S4 | 20.4R3-S4 |
| juniper_networks | junos_os | >= 21.1 < 21.1R3-S2 | 21.1R3-S2 |
| juniper_networks | junos_os | >= 21.2 < 21.2R3-S1 | 21.2R3-S1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ch96-rh97-j6j3: A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the d
ghsa_unreviewed·2022-10-18
CVE-2022-22245 [MEDIUM] CWE-22 GHSA-ch96-rh97-j6j3: A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the d
A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the device by bypassing validation checks built into Junos OS. The attacker should not be able to execute the file due to validation checks built into Junos OS. Successful exploitation of this vulnerability could lead to loss of filesystem integrity. This issue affects Juniper Networks Junos OS: all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R3-S9; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior
Juniper
CVE-2022-22245: A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the d
vendor_juniper·2022-10-18·CVSS 4.3
CVE-2022-22245 [MEDIUM] CWE-23 CVE-2022-22245: A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the d
CVE-2022-22245: A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the device by bypassing validation checks built into Junos OS. The attacker should not be able to execute the file due to validation checks built into Junos OS. Successful exploitation of this vulnerability could lead to loss of filesystem integrity. This issue affects Juniper Networks Junos OS: all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R3-S9; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S1; 21.
Suricata
ET MALWARE Potential Juniper Path Traversal RCE Attempt (CVE-2022-22245)
suricata·2022-10-28·CVSS 4.3
CVE-2022-22245 [MEDIUM] ET MALWARE Potential Juniper Path Traversal RCE Attempt (CVE-2022-22245)
ET MALWARE Potential Juniper Path Traversal RCE Attempt (CVE-2022-22245)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Potential Juniper Path Traversal RCE Attempt (CVE-2022-22245)"; flow:established,to_server; http.request_line; content:"POST|20|/Upload.php|20|"; startswith; http.request_body; content:"fileName"; content:"|5c 2e 2e 5c 2e 2e 5c|"; distance:0; fast_pattern; reference:url,octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/; reference:cve,2022-22245; classtype:trojan-activity; sid:2039599; rev:2; metadata:created_at 2022_10_28, cve CVE_2022_22245, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_11_26
No public exploits indexed.
No writeups or analysis indexed.
2022-10-18
Published