Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2022-22156

An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a system script is fetched from a remote source at a specified HTTPS URL, which may compromise the integrity and confidentiality of the device. The following command can be executed by an administrator via the CLI to refresh a script from a remote location, which is affected from this vulnerability: >request system scripts refresh-from (commit | event | extension-service | op | snmp) file filename url <https-url> This issue affects: Juniper Networks Junos OS All versions prior to 18.4R2-S9, 18.4R3-S9; 19.1 versions prior to 19.1R2-S3, 19.1R3-S7; 19.2 versions prior to 19.2R1-S7, 19.2R3-S3; 19.3 versions prior to 19.3R3-S4; 19.4 versions prior to 19.4R3-S7; 20.1 versions prior to 20.1R2-S2, 20.1R3; 20.2 versions prior to 20.2R3; 20.3 versions prior to 20.3R2-S1, 20.3R3; 20.4 versions prior to 20.4R2; 21.1 versions prior to 21.1R1-S1, 21.1R2.

  • Published: Jan 19, 2022
  • Updated: Apr 14, 2023
  • CVE: CVE-2022-22156
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.4
  • AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS v2:

  • Severity: Medium
  • Score: 5.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:N
Software From Fixed in
juniper / junos 18.4-r1 18.4-r1.x
juniper / junos 18.4 18.4.x
juniper / junos 18.4-r1-s1 18.4-r1-s1.x
juniper / junos 18.4-r1-s3 18.4-r1-s3.x
juniper / junos 18.4-r1-s4 18.4-r1-s4.x
juniper / junos 18.4-r1-s2 18.4-r1-s2.x
juniper / junos 19.1-r1 19.1-r1.x
juniper / junos 19.1 19.1.x
juniper / junos 19.2-r1 19.2-r1.x
juniper / junos 18.4-r2 18.4-r2.x
juniper / junos 19.1-r1-s1 19.1-r1-s1.x
juniper / junos 19.1-r1-s3 19.1-r1-s3.x
juniper / junos 19.1-r1-s2 19.1-r1-s2.x
juniper / junos 18.4-r1-s5 18.4-r1-s5.x
juniper / junos 19.2-r1-s1 19.2-r1-s1.x
juniper / junos 19.2-r1-s2 19.2-r1-s2.x
juniper / junos 18.4-r2-s1 18.4-r2-s1.x
juniper / junos 19.3 19.3.x
juniper / junos 19.3-r1 19.3-r1.x
juniper / junos 19.2 19.2.x
juniper / junos 18.4-r2-s2 18.4-r2-s2.x
juniper / junos 19.2-r1-s3 19.2-r1-s3.x
juniper / junos 19.4-r1 19.4-r1.x
juniper / junos 19.3-r2 19.3-r2.x
juniper / junos 19.1-r2 19.1-r2.x
juniper / junos 18.4-r3 18.4-r3.x
juniper / junos 18.4-r2-s3 18.4-r2-s3.x
juniper / junos 19.3-r2-s1 19.3-r2-s1.x
juniper / junos 19.3-r1-s1 19.3-r1-s1.x
juniper / junos 19.2-r1-s4 19.2-r1-s4.x
juniper / junos 20.1-r1 20.1-r1.x
juniper / junos 19.4-r1-s1 19.4-r1-s1.x
juniper / junos 19.3-r2-s2 19.3-r2-s2.x
juniper / junos 19.1-r1-s4 19.1-r1-s4.x
juniper / junos 18.4-r1-s6 18.4-r1-s6.x
juniper / junos 18.4-r3-s2 18.4-r3-s2.x
juniper / junos 18.4-r3-s1 18.4-r3-s1.x
juniper / junos 18.4-r2-s4 18.4-r2-s4.x
juniper / junos 19.1-r2-s1 19.1-r2-s1.x
juniper / junos 19.1-r3 19.1-r3.x
juniper / junos 19.1-r3-s1 19.1-r3-s1.x
juniper / junos 19.4-r1-s2 19.4-r1-s2.x
juniper / junos 20.1-r1-s1 20.1-r1-s1.x
juniper / junos 20.2-r1 20.2-r1.x
juniper / junos 20.1-r1-s2 20.1-r1-s2.x
juniper / junos 20.1-r1-s3 20.1-r1-s3.x
juniper / junos 19.4-r2 19.4-r2.x
juniper / junos 19.4-r2-s1 19.4-r2-s1.x
juniper / junos 19.3-r2-s3 19.3-r2-s3.x
juniper / junos 19.1-r3-s2 19.1-r3-s2.x
juniper / junos 18.4-r3-s3 18.4-r3-s3.x
juniper / junos 18.4-r3-s4 18.4-r3-s4.x
juniper / junos 19.2-r2 19.2-r2.x
juniper / junos 19.3-r2-s4 19.3-r2-s4.x
juniper / junos 20.2-r1-s1 20.2-r1-s1.x
juniper / junos 20.2-r1-s2 20.2-r1-s2.x
juniper / junos 19.4-r2-s2 19.4-r2-s2.x
juniper / junos 19.2-r3 19.2-r3.x
juniper / junos 18.4-r3-s5 18.4-r3-s5.x
juniper / junos 19.4-r3 19.4-r3.x
juniper / junos 19.3-r2-s5 19.3-r2-s5.x
juniper / junos 19.3-r3 19.3-r3.x
juniper / junos 19.2-r1-s5 19.2-r1-s5.x
juniper / junos 19.1-r3-s3 19.1-r3-s3.x
juniper / junos 18.4-r2-s5 18.4-r2-s5.x
juniper / junos 18.4-r2-s6 18.4-r2-s6.x
juniper / junos 19.1-r1-s5 19.1-r1-s5.x
juniper / junos 18.4-r1-s7 18.4-r1-s7.x
juniper / junos 20.3-r1 20.3-r1.x
juniper / junos 19.2-r2-s1 19.2-r2-s1.x
juniper / junos 20.1-r1-s4 20.1-r1-s4.x
juniper / junos 19.1-r3-s4 19.1-r3-s4.x
juniper / junos 18.4-r3-s6 18.4-r3-s6.x
juniper / junos 20.3-r1-s1 20.3-r1-s1.x
juniper / junos 20.2-r1-s3 20.2-r1-s3.x
juniper / junos 19.2-r3-s1 19.2-r3-s1.x
juniper / junos 18.4-r3-s7 18.4-r3-s7.x
juniper / junos 19.4-r3-s1 19.4-r3-s1.x
juniper / junos 19.4-r2-s3 19.4-r2-s3.x
juniper / junos 20.2-r2 20.2-r2.x
juniper / junos 20.2-r2-s1 20.2-r2-s1.x
juniper / junos 19.4-r1-s3 19.4-r1-s3.x
juniper / junos 19.2-r1-s6 19.2-r1-s6.x
juniper / junos 19.1-r2-s2 19.1-r2-s2.x
juniper / junos 20.4-r1 20.4-r1.x
juniper / junos 20.2-r2-s2 20.2-r2-s2.x
juniper / junos 20.1-r2 20.1-r2.x
juniper / junos 20.1-r2-s1 20.1-r2-s1.x
juniper / junos 20.4-r1-s1 20.4-r1-s1.x
juniper / junos 19.1-r1-s6 19.1-r1-s6.x
juniper / junos 20.2-r2-s3 20.2-r2-s3.x
juniper / junos 20.3-r2 20.3-r2.x
juniper / junos 19.3-r3-s1 19.3-r3-s1.x
juniper / junos 18.4-r2-s7 18.4-r2-s7.x
juniper / junos 21.1-r1 21.1-r1.x
juniper / junos 19.4-r3-s2 19.4-r3-s2.x
juniper / junos 19.4-r3-s3 19.4-r3-s3.x
juniper / junos 19.4-r3-s4 19.4-r3-s4.x
juniper / junos 19.3-r3-s2 19.3-r3-s2.x
juniper / junos 19.2-r3-s2 19.2-r3-s2.x
juniper / junos 18.4-r2-s8 18.4-r2-s8.x
juniper / junos 19.1-r3-s5 19.1-r3-s5.x
juniper / junos 18.4-r3-s8 18.4-r3-s8.x
juniper / junos 19.4-r2-s4 19.4-r2-s4.x
juniper / junos 19.4-r3-s5 19.4-r3-s5.x
juniper / junos 19.4-r1-s4 19.4-r1-s4.x
juniper / junos 19.1-r3-s6 19.1-r3-s6.x
juniper / junos 19.4-r2-s5 19.4-r2-s5.x
juniper / junos 19.3-r3-s3 19.3-r3-s3.x
juniper / junos 19.4-r3-s6 19.4-r3-s6.x
juniper / junos 19.3-r2-s6 19.3-r2-s6.x
juniper / junos - 18.3.x