CVE-2022-22238
Last modified
CVE-2022-22238 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When an incoming RESV message corresponding to a protected LSP is malformed it causes an incorrect internal state resulting in an rpd core. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When an incoming RESV message corresponding to a protected LSP is malformed it causes an incorrect internal state resulting in an rpd core. This issue affects: Juniper Networks Junos OS All versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S6; 19.4 versions prior to 19.4R3-S8; 20.1 versions prior to 20.1R3-S2; 20.2 versions prior to 20.2R3-S3; 20.3 versions prior to 20.3R3-S2; 20.4 versions prior to 20.4R3-S1; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R1-S2, 21.2R3; 21.3 versions prior to 21.3R2. Juniper Networks Junos OS Evolved All versions prior to 20.2R3-S3-EVO; 20.3-EVO version 20.3R1-EVO and later versions; 20.4-EVO versions prior to 20.4R3-S1-EVO; 21.1-EVO version 21.1R1-EVO and later versions; 21.2-EVO version 21.2R1-EVO and later versions; 21.3-EVO versions prior to 21.3R2-EVO.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | < 19.2 | — |
| Juniper | Junos | 19.2 | — |
| Juniper | Junos | 19.3 | — |
| Juniper | Junos | 19.4 | — |
| Juniper | Junos | 20.1 | — |
| Juniper | Junos | 20.2 | — |
| Juniper | Junos | 20.3 | — |
| Juniper | Junos | 20.4 | — |
| Juniper | Junos | 21.1 | — |
| Juniper | Junos | 21.2 | — |
| Juniper | Junos | 21.3 | — |
| Juniper | Junos Os Evolved | < 20.2 | — |
| Juniper | Junos Os Evolved | 20.2 | — |
| Juniper | Junos Os Evolved | 20.3 | R1 |
| Juniper | Junos Os Evolved | 20.4 | — |
| Juniper | Junos Os Evolved | 21.1 | R1 |
| Juniper | Junos Os Evolved | 21.2 | R1 |
| Juniper | Junos Os Evolved | 21.3 | — |
References
- https://kb.juniper.net/JSA69894Vendor Advisory
- https://kb.juniper.net/JSA69894Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-22238?
How severe is CVE-2022-22238?
How do I fix CVE-2022-22238?
Are you affected by CVE-2022-22238?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
