Improper Check or Handling of Exceptional Conditions in Junos OS - CVE-2022-22218

 

Improper Check or Handling of Exceptional Conditions in Junos OS - CVE-2022-22218

Published: October 12, 2022


Vulnerability identifier: #VU68274
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22218
CWE-ID: CWE-703
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling when using Certificate Management Protocol Version 2 (CMPv2) auto re-enrollment. A remote attacker can send a malformed response from the Certificate Authority (CA) server and crash the pkid process.

The vulnerability affects Juniper Networks Junos OS on SRX Series.


Affected software

Junos OS

How to mitigate CVE-2022-22218

Install updates from vendor's website.

Junos OS - addressed in versions 19.1R3-S9, 19.2R3-S6, 19.3R3-S7, 19.4R2-S7, 19.4R3-S9, 20.2R3-S5, 20.3R3-S4, 20.4R3-S4, 21.1R3-S1, 21.2R3, 21.3R2, 21.4R1-S2, 21.4R2, 22.1R1

External References

Related Security Bulletins