SB2022071366 - Information exposure in Juniper Junos OS



SB2022071366 - Information exposure in Juniper Junos OS

Published: July 13, 2022

Security Bulletin ID SB2022071366
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information exposure (CVE-ID: CVE-2022-22216)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the PFE of Juniper Networks Junos OS on PTX Series and QFX10k Series allows an adjacent unauthenticated attacker to gain access to sensitive information.

 PTX1000 and PTX10000 Series, and QFX10000 Series and PTX5000 Series devices sometimes do not reliably pad Ethernet packets, and thus some packets can contain fragments of system memory or data from previous packets.


Remediation

Install update from vendor's website.