Inefficient algorithmic complexity in Junos OS - CVE-2022-22153

 

Inefficient algorithmic complexity in Junos OS - CVE-2022-22153

Published: January 17, 2022


Vulnerability identifier: #VU59632
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22153
CWE-ID: CWE-407
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack.

The vulnerability exists due to insufficient algorithmic complexity along with an error of resource allocation in the flow processing daemon (flowd) on SRX Series and MX Series with SPC3. A remote attacker can cause latency in transit packet processing and even packet loss, if transit traffic includes a significant percentage (> 5%) of fragmented packets.


Affected software

Junos OS

How to mitigate CVE-2022-22153

Install updates from vendor's website.

Junos OS - addressed in versions 18.2R3, 18.3R3, 18.4R2-S9, 18.4R3, 19.1R2, 19.2R1-S1, 19.2R2, 19.3R1

External References

Related Security Bulletins