CVE-2022-22201
Last modified
CVE-2022-22201 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). On SRX5000 Series with SPC3, SRX4000 Series, and vSRX, when PowerMode IPsec is configured and a malformed ESP packet matching an established IPsec tunnel is received the PFE crashes. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). On SRX5000 Series with SPC3, SRX4000 Series, and vSRX, when PowerMode IPsec is configured and a malformed ESP packet matching an established IPsec tunnel is received the PFE crashes. This issue affects Juniper Networks Junos OS on SRX5000 Series with SPC3, SRX4000 Series, and vSRX: All versions prior to 19.4R2-S6, 19.4R3-S7; 20.1 versions prior to 20.1R3-S3; 20.2 versions prior to 20.2R3-S4; 20.3 versions prior to 20.3R3-S3; 20.4 versions prior to 20.4R3-S2; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R3; 21.3 versions prior to 21.3R1-S2, 21.3R2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | < 19.4 | — |
| Juniper | Junos | 19.4 | — |
| Juniper | Junos | 20.1 | — |
| Juniper | Junos | 20.2 | — |
| Juniper | Junos | 20.3 | — |
| Juniper | Junos | 20.4 | — |
| Juniper | Junos | 21.1 | — |
| Juniper | Junos | 21.2 | — |
| Juniper | Junos | 21.3 | R1 |
References
- https://kb.juniper.net/JSA69900Vendor Advisory
- https://kb.juniper.net/JSA69900Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-22201?
How severe is CVE-2022-22201?
How do I fix CVE-2022-22201?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-22196An Improper Check for Unusual or Exceptional Conditions vuln…6.5
- CVE-2022-22197An Operation on a Resource after Expiration or Release vulne…7.5
- CVE-2022-22198An Access of Uninitialized Pointer vulnerability in the SIP …7.5
- CVE-2022-22199Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-2220Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-22200Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-22202An Improper Handling of Exceptional Conditions vulnerability…6.5
- CVE-2022-22203An Incorrect Comparison vulnerability in PFE of Juniper Netw…6.5
- CVE-2022-22204An Improper Release of Memory Before Removing Last Reference…5.3
- CVE-2022-22205A Missing Release of Memory after Effective Lifetime vulnera…7.5
- CVE-2022-22206A Buffer Overflow vulnerability in the PFE of Juniper Networ…7.5
- CVE-2022-22207A Use After Free vulnerability in the Advanced Forwarding To…7.5
Are you affected by CVE-2022-22201?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
