Record summary

CVE-2022-22242 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web. This issue affects Juniper Networks Junos OS all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R2; 22.1 versions prior to 22.1R2.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 25, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 9, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE ListBefore 19.1R3-S9affected
19.2 to < 19.2R3-S6affected
19.3 to < 19.3R3-S7affected
19.4 to < 19.4R2-S7, 19.4R3-S8affected
20.1 to < 20.1R3-S5affected
20.2 to < 20.2R3-S5affected
20.3 to < 20.3R3-S5affected
20.4 to < 20.4R3-S4affected
21.1 to < 21.1R3-S4affected
21.2 to < 21.2R3-S1affected
21.3 to < 21.3R3affected
21.4 to < 21.4R2affected
Showing 12 of 13 version ranges

Nuclei templates

1
ProjectDiscoveryMEDIUMJuniper Web Device Manager - Cross-Site ScriptingCVSS 6.1

Juniper Web Device Manager (J-Web) in Junos OS contains a cross-site scripting vulnerability. This can allow an unauthenticated attacker to run malicious scripts reflected off J-Web to the victim's browser in the context of their session within J-Web, which can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue affects all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R2; 22.1 versions prior to 22.1R2.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the targeted user's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the latest security patches or updates provided by Juniper Networks to mitigate this vulnerability.

WeaknessesCWE-79
AuthorsEvergreenCartoons
Template tagscve2022cvexssjuniperjunosvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*
Shodan: title:"Juniper Web Device Manager"
Shodan: http.title:"juniper web device manager"
FOFA: title="juniper web device manager"
Google: intitle:"juniper web device manager"

Source: ProjectDiscovery

References

2