CVE-2022-22242

High PUBLISHED

Junos OS: Cross-site Scripting (XSS) vulnerability in J-Web

Juniper Networks · Junos OS

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
6.1 Medium

At a Glance

A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web. This issue affects Juniper Networks Junos OS all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R2; 22.1 versions prior to 22.1R2.

nuclei_scanner
CVE Published
Oct 18, 2022
Exploitation Reported
Jul 21, 2025
CVSS
6.1 Medium
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
Juniper Networks
Junos OS

unspecified to < 19.1R3-S9

Affected
Juniper Networks
Junos OS

19.2 to < 19.2R3-S6

Affected
Juniper Networks
Junos OS

19.3 to < 19.3R3-S7

Affected
Juniper Networks
Junos OS

19.4 to < 19.4R2-S7, 19.4R3-S8

Affected
Juniper Networks
Junos OS

20.1 to < 20.1R3-S5

Affected
Juniper Networks
Junos OS

20.2 to < 20.2R3-S5

Affected
Juniper Networks
Junos OS

20.3 to < 20.3R3-S5

Affected
Juniper Networks
Junos OS

20.4 to < 20.4R3-S4

Affected
Juniper Networks
Junos OS

21.1 to < 21.1R3-S4

Affected
Juniper Networks
Junos OS

21.2 to < 21.2R3-S1

Affected
Juniper Networks
Junos OS

21.3 to < 21.3R3

Affected
Juniper Networks
Junos OS

21.4 to < 21.4R2

Affected
Juniper Networks
Junos OS

22.1 to < 22.1R2

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.