CVE-2022-22205
Last modified
CVE-2022-22205 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A Missing Release of Memory after Effective Lifetime vulnerability in the Application Quality of Experience (appqoe) subsystem of the PFE of Juniper Networks Junos OS on SRX Series allows an unauthenticated network based attacker to cause a Denial of Service (DoS). Upon receiving specific traffic a memory leak will occur. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
A Missing Release of Memory after Effective Lifetime vulnerability in the Application Quality of Experience (appqoe) subsystem of the PFE of Juniper Networks Junos OS on SRX Series allows an unauthenticated network based attacker to cause a Denial of Service (DoS). Upon receiving specific traffic a memory leak will occur. Sustained processing of such specific traffic will eventually lead to an out of memory condition that prevents all services from continuing to function, and requires a manual restart to recover. A device is only vulnerable when advance(d) policy based routing (APBR) is configured and AppQoE (sla rule) is not configured for these APBR rules. This issue affects Juniper Networks Junos OS on SRX Series: 20.3 versions prior to 20.3R3-S2; 20.4 versions prior to 20.4R3-S2; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R2-S1, 21.2R3; 21.3 versions prior to 21.3R1-S2, 21.3R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.3R1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | 20.3 | — |
| Juniper | Junos | 20.4 | — |
| Juniper | Junos | 21.1 | — |
| Juniper | Junos | 21.2 | — |
| Juniper | Junos | 21.3 | R1 |
References
- https://kb.juniper.net/JSA69709Vendor Advisory
- https://kb.juniper.net/JSA69709Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-22205?
How severe is CVE-2022-22205?
How do I fix CVE-2022-22205?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-2220Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-22200Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-22201An Improper Validation of Specified Index, Position, or Offs…7.5
- CVE-2022-22202An Improper Handling of Exceptional Conditions vulnerability…6.5
- CVE-2022-22203An Incorrect Comparison vulnerability in PFE of Juniper Netw…6.5
- CVE-2022-22204An Improper Release of Memory Before Removing Last Reference…5.3
- CVE-2022-22206A Buffer Overflow vulnerability in the PFE of Juniper Networ…7.5
- CVE-2022-22207A Use After Free vulnerability in the Advanced Forwarding To…7.5
- CVE-2022-22208A Use After Free vulnerability in the Routing Protocol Daemo…5.9
- CVE-2022-22209A Missing Release of Memory after Effective Lifetime vulnera…7.5
- CVE-2022-2221Information Exposure vulnerability in My Account Settings of…6.5
- CVE-2022-22210A NULL Pointer Dereference vulnerability in the Packet Forwa…6.5
Are you affected by CVE-2022-22205?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
