Vulnerability identifier: #VU59563
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22173
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak in the Public Key Infrastructure daemon (pkid). In a scenario where Public Key Infrastructure (PKI) is used in
combination with Certificate Revocation List (CRL), if the CRL fails to
download the memory allocated to store the CRL is not released. Repeated
occurrences will eventually consume all available memory and lead to an
inoperable state of the affected system causing a DoS.
Affected software
Junos OS
How to mitigate CVE-2022-22173
Install updates from vendor's website.
Junos OS - addressed in versions 18.3R3-S6, 18.4R2-S9, 18.4R3-S10, 19.1R2-S3, 19.1R3-S7, 19.2R1-S8, 19.2R3-S4, 19.3R3-S4, 19.4R2-S5, 19.4R3-S5, 20.1R3-S1, 20.2R3-S2, 20.3R3-S1, 20.4R3, 21.1R2, 21.1R3, 21.2R1-S1, 21.2R2, 21.3R1
External References
Related Security Bulletins