Improper Initialization in Junos OS and Junos OS Evolved - CVE-2022-22169
Published: January 12, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper initialization in the routing protocol daemon (rpd) . A remote attacker can send specific packets in certain orders and at specific timings to force OSPFv3 to unexpectedly enter graceful-restart (GR helper mode) even though there is not any Grace-LSA received in OSPFv3 causing a Denial of Service (DoS)
Affected software
Junos OS Evolved
How to mitigate CVE-2022-22169
Junos OS Evolved - addressed in versions 21.2R2-EVO, 21.3R1-EVO