CVE-2022-22226
Last modified
CVE-2022-22226 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. In VxLAN scenarios on EX4300-MP, EX4600, QFX5000 Series devices an Uncontrolled Memory Allocation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated adjacently located attacker sending specific packets to cause a Denial of Service (DoS) condition by crashing one or more PFE's when they are received and processed by the device. Upon automatic restart of the PFE, continued processing of these packets will cause the memory leak to reappear. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
In VxLAN scenarios on EX4300-MP, EX4600, QFX5000 Series devices an Uncontrolled Memory Allocation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated adjacently located attacker sending specific packets to cause a Denial of Service (DoS) condition by crashing one or more PFE's when they are received and processed by the device. Upon automatic restart of the PFE, continued processing of these packets will cause the memory leak to reappear. Depending on the volume of packets received the attacker may be able to create a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS on EX4300-MP, EX4600, QFX5000 Series: 17.1 version 17.1R1 and later versions prior to 17.3R3-S12; 17.4 versions prior to 17.4R2-S13, 17.4R3-S5; 18.1 versions prior to 18.1R3-S13; 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R1-S8, 18.4R2-S6, 18.4R3-S6; 19.1 versions prior to 19.1R3-S4; 19.2 versions prior to 19.2R1-S7, 19.2R3-S1; 19.3 versions prior to 19.3R2-S6, 19.3R3-S1; 19.4 versions prior to 19.4R1-S4, 19.4R2-S4, 19.4R3-S1; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R2-S3, 20.2R3; 20.3 versions prior to 20.3R2. This issue does not affect Junos OS versions prior to 17.1R1.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | 17.1 | R1 |
| Juniper | Junos | 17.2 | — |
| Juniper | Junos | 17.2x75 | — |
| Juniper | Junos | 17.3 | — |
| Juniper | Junos | 17.4 | — |
| Juniper | Junos | 18.1 | — |
| Juniper | Junos | 18.2 | — |
| Juniper | Junos | 18.3 | — |
| Juniper | Junos | 18.4 | — |
| Juniper | Junos | 19.1 | — |
| Juniper | Junos | 19.2 | — |
| Juniper | Junos | 19.3 | — |
| Juniper | Junos | 19.4 | — |
| Juniper | Junos | 20.1 | — |
| Juniper | Junos | 20.2 | — |
| Juniper | Junos | 20.3 | — |
References
- https://kb.juniper.net/JSA69876Vendor Advisory
- https://kb.juniper.net/JSA69876Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-22226?
How severe is CVE-2022-22226?
How do I fix CVE-2022-22226?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-2222The Download Monitor WordPress plugin before 4.5.91 does not…4.9
- CVE-2022-22220A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerab…5.9
- CVE-2022-22221An Improper Neutralization of Special Elements vulnerability…7.8
- CVE-2022-22223On QFX10000 Series devices using Juniper Networks Junos OS w…7.5
- CVE-2022-22224An Improper Check or Handling of Exceptional Conditions vuln…6.5
- CVE-2022-22225A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerab…5.9
- CVE-2022-22227An Improper Check for Unusual or Exceptional Conditions vuln…5.3
- CVE-2022-22228An Improper Validation of Specified Type of Input vulnerabil…7.5
- CVE-2022-22229An Improper Neutralization of Input During Web Page Generati…8.4
- CVE-2022-2223The WordPress plugin Image Slider is vulnerable to Cross-Sit…4.3
- CVE-2022-22230An Improper Input Validation vulnerability in the Routing Pr…6.5
- CVE-2022-22231An Unchecked Return Value to NULL Pointer Dereference vulner…7.5
Are you affected by CVE-2022-22226?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
