CVE-2022-22181

A reflected Cross-site Scripting (XSS) vulnerability in J-Web of Juniper Networks Junos OS allows a network-based authenticated attacker to run malicious scripts reflected off J-Web to the victim's browser in the context of their session within J-Web. This may allow the attacker to gain control of the device or attack other authenticated user sessions. This issue affects: Juniper Networks Junos OS All versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R3-S9; 19.1 versions prior to 19.1R3-S6; 19.2 versions prior to 19.2R3-S3; 19.3 versions prior to 19.3R2-S6, 19.3R3-S3; 19.4 versions prior to 19.4R3-S5; 20.1 versions prior to 20.1R3-S4; 20.2 versions prior to 20.2R3-S2; 20.3 versions prior to 20.3R3; 20.4 versions prior to 20.4R3; 21.1 versions prior to 21.1R1-S1, 21.1R2.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
juniperCNA
8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
juniperjunos
𝑥
< 18.3
juniperjunos
18.3
juniperjunos
18.3:r
juniperjunos
18.3:r1
juniperjunos
18.3:r1-s1
juniperjunos
18.3:r1-s2
juniperjunos
18.3:r1-s3
juniperjunos
18.3:r1-s4
juniperjunos
18.3:r1-s5
juniperjunos
18.3:r1-s6
juniperjunos
18.3:r2
juniperjunos
18.3:r2-s1
juniperjunos
18.3:r2-s2
juniperjunos
18.3:r2-s3
juniperjunos
18.3:r2-s4
juniperjunos
18.3:r3
juniperjunos
18.3:r3-s1
juniperjunos
18.3:r3-s2
juniperjunos
18.3:r3-s3
juniperjunos
18.3:r3-s4
juniperjunos
18.4
juniperjunos
18.4:r1
juniperjunos
18.4:r1-s1
juniperjunos
18.4:r1-s2
juniperjunos
18.4:r1-s3
juniperjunos
18.4:r1-s4
juniperjunos
18.4:r1-s5
juniperjunos
18.4:r1-s6
juniperjunos
18.4:r1-s7
juniperjunos
18.4:r2
juniperjunos
18.4:r2-s1
juniperjunos
18.4:r2-s2
juniperjunos
18.4:r2-s3
juniperjunos
18.4:r2-s4
juniperjunos
18.4:r2-s5
juniperjunos
18.4:r2-s6
juniperjunos
18.4:r2-s7
juniperjunos
18.4:r2-s8
juniperjunos
18.4:r3
juniperjunos
18.4:r3-s1
juniperjunos
18.4:r3-s2
juniperjunos
18.4:r3-s3
juniperjunos
18.4:r3-s4
juniperjunos
18.4:r3-s5
juniperjunos
18.4:r3-s6
juniperjunos
18.4:r3-s7
juniperjunos
18.4:r3-s8
juniperjunos
19.1
juniperjunos
19.1:r1
juniperjunos
19.1:r1-s1
juniperjunos
19.1:r1-s2
juniperjunos
19.1:r1-s3
juniperjunos
19.1:r1-s4
juniperjunos
19.1:r1-s5
juniperjunos
19.1:r1-s6
juniperjunos
19.1:r2
juniperjunos
19.1:r2-s1
juniperjunos
19.1:r2-s2
juniperjunos
19.1:r3
juniperjunos
19.1:r3-s1
juniperjunos
19.1:r3-s2
juniperjunos
19.1:r3-s3
juniperjunos
19.1:r3-s4
juniperjunos
19.1:r3-s5
juniperjunos
19.2
juniperjunos
19.2:r1
juniperjunos
19.2:r1-s1
juniperjunos
19.2:r1-s2
juniperjunos
19.2:r1-s3
juniperjunos
19.2:r1-s4
juniperjunos
19.2:r1-s5
juniperjunos
19.2:r1-s6
juniperjunos
19.2:r1-s7
juniperjunos
19.2:r2
juniperjunos
19.2:r2-s1
juniperjunos
19.2:r3
juniperjunos
19.2:r3-s1
juniperjunos
19.2:r3-s2
juniperjunos
19.3
juniperjunos
19.3:r1
juniperjunos
19.3:r1-s1
juniperjunos
19.3:r2
juniperjunos
19.3:r2-s1
juniperjunos
19.3:r2-s2
juniperjunos
19.3:r2-s3
juniperjunos
19.3:r2-s4
juniperjunos
19.3:r2-s5
juniperjunos
19.3:r3-s1
juniperjunos
19.3:r3-s2
juniperjunos
19.4
juniperjunos
19.4:r1
juniperjunos
19.4:r1-s1
juniperjunos
19.4:r1-s2
juniperjunos
19.4:r1-s3
juniperjunos
19.4:r1-s4
juniperjunos
19.4:r2
juniperjunos
19.4:r2-s1
juniperjunos
19.4:r2-s2
juniperjunos
19.4:r2-s3
juniperjunos
19.4:r2-s4
juniperjunos
19.4:r3
juniperjunos
19.4:r3-s1
juniperjunos
19.4:r3-s2
juniperjunos
19.4:r3-s3
juniperjunos
19.4:r3-s4
juniperjunos
20.1
juniperjunos
20.1:r1
juniperjunos
20.1:r1-s1
juniperjunos
20.1:r1-s2
juniperjunos
20.1:r1-s3
juniperjunos
20.1:r1-s4
juniperjunos
20.1:r2
juniperjunos
20.1:r2-s1
juniperjunos
20.1:r2-s2
juniperjunos
20.1:r3
juniperjunos
20.1:r3-s1
juniperjunos
20.1:r3-s2
juniperjunos
20.1:r3-s3
juniperjunos
20.2
juniperjunos
20.2:r1
juniperjunos
20.2:r1-s1
juniperjunos
20.2:r1-s2
juniperjunos
20.2:r1-s3
juniperjunos
20.2:r2
juniperjunos
20.2:r2-s1
juniperjunos
20.2:r2-s2
juniperjunos
20.2:r2-s3
juniperjunos
20.2:r3
juniperjunos
20.2:r3-s1
juniperjunos
20.3
juniperjunos
20.3:r1
juniperjunos
20.3:r1-s1
juniperjunos
20.3:r2
juniperjunos
20.3:r2-s1
juniperjunos
20.4
juniperjunos
20.4:r1
juniperjunos
20.4:r1-s1
juniperjunos
20.4:r2
juniperjunos
20.4:r2-s1
juniperjunos
20.4:r2-s2
juniperjunos
21.1
juniperjunos
21.1:r1
𝑥
= Vulnerable software versions