CVE-2022-22184
- EPSS 0.2%
- Published 22.12.2022 22:15:11
- Last modified 21.11.2024 06:46:20
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). If a BGP update message is received...
CVE-2022-22242
- EPSS 85.71%
- Published 18.10.2022 03:15:11
- Last modified 21.11.2024 06:46:28
A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web. Th...
CVE-2022-22243
- EPSS 0.42%
- Published 18.10.2022 03:15:11
- Last modified 21.11.2024 06:46:28
An XPath Injection vulnerability due to Improper Input Validation in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to add an XPath command to the XPath stream, which may allow chaining to other unspecified vulnerab...
CVE-2022-22244
- EPSS 0.96%
- Published 18.10.2022 03:15:11
- Last modified 21.11.2024 06:46:28
An XPath Injection vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker sending a crafted POST to reach the XPath channel, which may allow chaining to other unspecified vulnerabilities, leading to a par...
CVE-2022-22245
- EPSS 0.1%
- Published 18.10.2022 03:15:11
- Last modified 21.11.2024 06:46:28
A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the device by bypassing validation checks built into Junos OS. The attacker should not be able to execute...
CVE-2022-22246
- EPSS 0.27%
- Published 18.10.2022 03:15:11
- Last modified 21.11.2024 06:46:28
A PHP Local File Inclusion (LFI) vulnerability in the J-Web component of Juniper Networks Junos OS may allow a low-privileged authenticated attacker to execute an untrusted PHP file. By chaining this vulnerability with other unspecified vulnerabiliti...
CVE-2022-22249
- EPSS 0.11%
- Published 18.10.2022 03:15:11
- Last modified 21.11.2024 06:46:29
An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When there is a conti...
CVE-2022-22250
- EPSS 0.09%
- Published 18.10.2022 03:15:11
- Last modified 21.11.2024 06:46:29
An Improper Control of a Resource Through its Lifetime vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows unauthenticated adjacent attacker to cause a Denial of Service (DoS). In an EVPN-MPLS scen...
CVE-2022-22251
- EPSS 0.03%
- Published 18.10.2022 03:15:11
- Last modified 21.11.2024 06:46:29
On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker to elevate their permissions t...
CVE-2022-22228
- EPSS 0.18%
- Published 18.10.2022 03:15:10
- Last modified 21.11.2024 06:46:26
An Improper Validation of Specified Type of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an attacker to cause an RPD memory leak leading to a Denial of Service (DoS). This memory leak only occurs when t...