Information disclosure in Juniper Junos OS - CVE-2022-22162
Published: January 13, 2022
Juniper Junos OS
Juniper Networks, Inc.
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to excessive data output in the CLI. A local user can force the system to generate error messages that contain enough information to elevate privileges on the system to the level of any other user logged in via J-Web at this time.
Successful exploitation of the vulnerability may allow an attacker to compromise the device.