Vulnerabilities > Juniper > Junos > 21.2

DATE CVE VULNERABILITY TITLE RISK
2022-10-18 CVE-2022-22235 Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper Junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based, attacker to cause Denial of Service (DoS).
network
low complexity
juniper CWE-754
7.5
2022-10-18 CVE-2022-22236 Access of Uninitialized Pointer vulnerability in Juniper Junos
An Access of Uninitialized Pointer vulnerability in SIP Application Layer Gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).
network
low complexity
juniper CWE-824
7.5
2022-10-18 CVE-2022-22237 Improper Authentication vulnerability in Juniper Junos
An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause an impact on confidentiality or integrity.
network
low complexity
juniper CWE-287
6.5
2022-10-18 CVE-2022-22238 Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper Junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).
low complexity
juniper CWE-754
6.5
2022-10-18 CVE-2022-22240 Allocation of Resources Without Limits or Throttling vulnerability in Juniper Junos
An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated low privileged attacker to cause a Denial of Sevice (DoS).
local
low complexity
juniper CWE-770
5.5
2022-10-18 CVE-2022-22241 Deserialization of Untrusted Data vulnerability in Juniper Junos
An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without proper authorization.
network
low complexity
juniper CWE-502
critical
9.8
2022-10-18 CVE-2022-22242 Cross-site Scripting vulnerability in Juniper Junos
A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web.
network
low complexity
juniper CWE-79
6.1
2022-10-18 CVE-2022-22243 XML Injection (aka Blind XPath Injection) vulnerability in Juniper Junos
An XPath Injection vulnerability due to Improper Input Validation in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to add an XPath command to the XPath stream, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss of confidentiality.
network
low complexity
juniper CWE-91
4.3
2022-10-18 CVE-2022-22244 XML Injection (aka Blind XPath Injection) vulnerability in Juniper Junos
An XPath Injection vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker sending a crafted POST to reach the XPath channel, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss of confidentiality.
network
low complexity
juniper CWE-91
5.3
2022-10-18 CVE-2022-22245 Path Traversal vulnerability in Juniper Junos
A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the device by bypassing validation checks built into Junos OS.
network
low complexity
juniper CWE-22
4.3