CVE-2022-22212
Last modified
CVE-2022-22212 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows unauthenticated network based attacker to cause a Denial of Service (DoS). On all Junos Evolved platforms hostbound protocols will be impacted by a high rate of specific hostbound traffic from ports on a PFE. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows unauthenticated network based attacker to cause a Denial of Service (DoS). On all Junos Evolved platforms hostbound protocols will be impacted by a high rate of specific hostbound traffic from ports on a PFE. Continued receipt of this amount of traffic will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks Junos OS Evolved: 21.2 versions prior to 21.2R3-EVO; 21.3 versions prior to 21.3R2-EVO. This issue does not affect Juniper Networks Junos OS Evolved versions prior to 21.2R1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos Os Evolved | 21.2 |
| Juniper | Junos Os Evolved | 21.3 |
References
- https://kb.juniper.net/JSA69716Vendor Advisory
- https://kb.juniper.net/JSA69716Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-22212?
How severe is CVE-2022-22212?
How do I fix CVE-2022-22212?
Are you affected by CVE-2022-22212?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
