CVE-2022-22154 is an External Control of Critical State Data vulnerability in Juniper Networks Junos OS, affecting Junos Fusion Satellite Devices (SDs) in versions prior to 18.4R3-S10, 19.1R3-S7, and 19.2R3-S4. An attacker with physical access to the cabling between an SD and its Aggregation Device (AD) can cause a denial of service (DoS) by redirecting the SD to an unauthorized AD. This vulnerability has a CVSS score of 6.8 (Medium), indicating high impact on confidentiality, integrity, and availability, but requires physical access to exploit. There is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:16.1:r1:*:*:*:*:*:* | ||
16.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:16.1:r2:*:*:*:*:*:* | ||
16.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:16.1:r3:*:*:*:*:*:* | ||
16.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:16.1:r3-s10:*:*:*:*:*:* | ||
16.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:16.1:r3-s11:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.