CVE-2022-22184
Last modified
CVE-2022-22184 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). If a BGP update message is received over an established BGP session, and that message contains a specific, optional transitive attribute, this session will be torn down with an update message error. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). If a BGP update message is received over an established BGP session, and that message contains a specific, optional transitive attribute, this session will be torn down with an update message error. This issue cannot propagate beyond an affected system as the processing error occurs as soon as the update is received. This issue is exploitable remotely as the respective attribute will propagate through unaffected systems and intermediate AS (if any). Continuous receipt of a BGP update containing this attribute will create a sustained Denial of Service (DoS) condition. Since this issue only affects 22.3R1, Juniper strongly encourages customers to move to 22.3R1-S1. Juniper SIRT felt that the need to promptly warn customers about this issue affecting the 22.3R1 versions of Junos OS and Junos OS Evolved warranted an Out of Cycle JSA. This issue affects: Juniper Networks Junos OS version 22.3R1. Juniper Networks Junos OS Evolved version 22.3R1-EVO. This issue does not affect: Juniper Networks Junos OS versions prior to 22.3R1. Juniper Networks Junos OS Evolved versions prior to 22.3R1-EVO.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | 22.3 | R1 |
| Juniper | Junos Os Evolved | 22.3 | R1 |
References
- https://kb.juniper.net/JSA70175Vendor Advisory
- https://kb.juniper.net/JSA70175Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-22184?
How severe is CVE-2022-22184?
How do I fix CVE-2022-22184?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-22179A Improper Validation of Specified Index, Position, or Offse…6.5
- CVE-2022-2218Cross-site Scripting (XSS) - Stored in GitHub repository ion…6.1
- CVE-2022-22180An Improper Check for Unusual or Exceptional Conditions vuln…7.5
- CVE-2022-22181A reflected Cross-site Scripting (XSS) vulnerability in J-We…5.4
- CVE-2022-22182A Cross-site Scripting (XSS) vulnerability in Juniper Networ…6.1
- CVE-2022-22183An Improper Access Control vulnerability in Juniper Networks…7.5
- CVE-2022-22185A vulnerability in Juniper Networks Junos OS on SRX Series, …7.5
- CVE-2022-22186Due to an Improper Initialization vulnerability in Juniper N…6.5
- CVE-2022-22187An Improper Privilege Management vulnerability in the Window…7.8
- CVE-2022-22188An Uncontrolled Memory Allocation vulnerability leading to a…7.5
- CVE-2022-22189An Incorrect Ownership Assignment vulnerability in Juniper N…7.8
- CVE-2022-2219The Unyson WordPress plugin before 2.7.27 does not sanitise …7.2
Are you affected by CVE-2022-22184?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
