SB2022011314 - Privilege escalation in Junos OS J-Web
Published: January 13, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2022-22162)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to excessive data output in the CLI. A local user can force the system to generate error messages that contain enough information to elevate privileges on the system to the level of any other user logged in via J-Web at this time.
Successful exploitation of the vulnerability may allow an attacker to compromise the device.
Remediation
Install update from vendor's website.