Release of invalid pointer or reference in Junos OS and Junos OS Evolved - CVE-2022-22177
Published: January 17, 2022
Vulnerability details
The vulnerability allows remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to release of illegal memory vulnerability in the snmpd daemon. A remote attacker can send specially SNMP packets to the snmpd daemon and crash it, resulting in a denial of service (DoS) attack.
Note, all SNMP version requests are affected.
Affected software
Junos OS Evolved
How to mitigate CVE-2022-22177
Junos OS Evolved - addressed in versions 21.2R3-EVO, 21.3R2-EVO, 21.4R1-EVO