Resource exhaustion in Junos OS and Junos OS Evolved - CVE-2022-22215
Published: July 16, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to failure to release file descriptors (e.g. delete the "respective/var/run/.env" file) in plugable authentication module (PAM) when handling gRPC connection termination events. A remote attacker can trigger inode exhaustion by initiating and terminating a large number of gRPC connections and perform a denial of service (DoS) attack.
Affected software
Junos OS Evolved
How to mitigate CVE-2022-22215
Junos OS Evolved - addressed in versions 20.4R3-EVO, 21.1R3-S1-EVO, 21.2R1-S1-EVO, 21.2R2-EVO, 21.3R1-EVO