SB2022071620 - Privilege escalation in Junos OS SRX and EX Series



SB2022071620 - Privilege escalation in Junos OS SRX and EX Series

Published: July 16, 2022

Security Bulletin ID SB2022071620
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) OS Command Injection (CVE-ID: CVE-2022-22221)

The vulnerability allows a local user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the 'request system download ...' and  'show system download ...' commands. A local user can pass specially crafted data to the affected CLI commands and execute arbitrary OS commands on the target system with elevated privileges.



Remediation

Install update from vendor's website.