Improper Handling of Exceptional Conditions in Junos OS and Junos OS Evolved - CVE-2022-22224

 

Improper Handling of Exceptional Conditions in Junos OS and Junos OS Evolved - CVE-2022-22224

Published: October 12, 2022


Vulnerability identifier: #VU68276
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22224
CWE-ID: CWE-755
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect error handling when processing malformed OSPF TLV within the periodic packet management daemon (PPMD) process. A remote attacker on the local network can send malformed OSPF TLV and cause the PPMD process to enter an infinite loop.


Affected software

Junos OS
Junos OS Evolved

How to mitigate CVE-2022-22224

Install updates from vendor's website.

Junos OS - addressed in versions 19.1R3-S9, 19.2R3-S5, 19.3R3-S3, 19.4R3-S9, 20.1R3, 20.2R3-S1, 20.3R3, 20.4R3, 21.1R2, 21.2R1
Junos OS Evolved - addressed in versions 20.4R3-S3-EVO, 21.1R2-EVO, 21.2R1-EVO

External References

Related Security Bulletins