CVE-2022-22160
Last modified
CVE-2022-22160 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An Unchecked Error Condition vulnerability in the subscriber management daemon (smgd) of Juniper Networks Junos OS allows an unauthenticated adjacent attacker to cause a crash of and thereby a Denial of Service (DoS). In a subscriber management / broadband edge environment if a single session group configuration contains dual-stack and a pp0 interface, smgd will crash and restart every time a PPPoE client sends a specific message. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
An Unchecked Error Condition vulnerability in the subscriber management daemon (smgd) of Juniper Networks Junos OS allows an unauthenticated adjacent attacker to cause a crash of and thereby a Denial of Service (DoS). In a subscriber management / broadband edge environment if a single session group configuration contains dual-stack and a pp0 interface, smgd will crash and restart every time a PPPoE client sends a specific message. This issue affects Juniper Networks Junos OS on MX Series: 16.1 version 16.1R1 and later versions prior to 18.4R3-S10; 19.1 versions prior to 19.1R2-S3, 19.1R3-S7; 19.2 versions prior to 19.2R1-S8, 19.2R3-S4; 19.3 versions prior to 19.3R3-S4; 19.4 versions prior to 19.4R3-S5; 20.1 versions prior to 20.1R3-S3; 20.2 versions prior to 20.2R3-S3; 20.3 versions prior to 20.3R3-S2; 20.4 versions prior to 20.4R3; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R2. This issue does not affect Juniper Networks Junos OS versions prior to 16.1R1.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | 16.1 | — |
| Juniper | Junos | 16.1x65 | — |
| Juniper | Junos | 16.1x70 | — |
| Juniper | Junos | 16.2 | — |
| Juniper | Junos | 17.1 | — |
| Juniper | Junos | 17.2 | — |
| Juniper | Junos | 17.2x75 | — |
| Juniper | Junos | 17.3 | — |
| Juniper | Junos | 17.4 | — |
| Juniper | Junos | 17.4r2 | — |
| Juniper | Junos | 18.1 | R1 |
| Juniper | Junos | 18.1x75 | — |
| Juniper | Junos | 18.2 | — |
| Juniper | Junos | 18.2x75 | — |
| Juniper | Junos | 18.2x75-d10 | — |
| Juniper | Junos | 18.2x75-d30 | — |
| Juniper | Junos | 18.3 | — |
| Juniper | Junos | 18.4 | — |
| Juniper | Junos | 19.1 | — |
| Juniper | Junos | 19.2 | — |
| Juniper | Junos | 19.3 | — |
| Juniper | Junos | 19.4 | — |
| Juniper | Junos | 20.1 | — |
| Juniper | Junos | 20.2 | — |
| Juniper | Junos | 20.3 | — |
| Juniper | Junos | 20.4 | — |
| Juniper | Junos | 21.1 | — |
| Juniper | Junos | 21.2 | — |
References
- https://kb.juniper.net/JSA11268Vendor Advisory
- https://kb.juniper.net/JSA11268Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-22160?
How severe is CVE-2022-22160?
How do I fix CVE-2022-22160?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-22155An Uncontrolled Resource Consumption vulnerability in the ha…6.5
- CVE-2022-22156An Improper Certificate Validation weakness in the Juniper N…7.4
- CVE-2022-22157A traffic classification vulnerability in Juniper Networks J…9.3
- CVE-2022-22158Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-22159A vulnerability in the NETISR network queue functionality of…7.5
- CVE-2022-2216Server-Side Request Forgery (SSRF) in GitHub repository ioni…9.8
- CVE-2022-22161An Uncontrolled Resource Consumption vulnerability in the ke…7.5
- CVE-2022-22162A Generation of Error Message Containing Sensitive Informati…7.8
- CVE-2022-22163An Improper Input Validation vulnerability in the Juniper DH…6.5
- CVE-2022-22164An Improper Initialization vulnerability in Juniper Networks…5.3
- CVE-2022-22165Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-22166An Improper Validation of Specified Quantity in Input vulner…6.5
Are you affected by CVE-2022-22160?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
