Improper handling of exceptional conditions in Junos OS Evolved - CVE-2022-22227

 

Improper handling of exceptional conditions in Junos OS Evolved - CVE-2022-22227

Published: October 14, 2022


Vulnerability identifier: #VU68328
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22227
CWE-ID: CWE-755
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper handling of errors in the Packet Forwarding Engine (PFE) when processing IPv6 transit traffic. A remote attacker can send specially crafted input through the device and cause increased CPU utilization, which can result in denial of service (DoS).


Affected software

Junos OS Evolved

How to mitigate CVE-2022-22227

Install updates from vendor's website.

Junos OS Evolved - addressed in versions 21.1R3-S2-EVO, 21.2R3-S2-EVO, 21.3R3-EVO, 21.4R1-S1-EVO, 21.4R2-EVO, 22.1R1-EVO

External References

Related Security Bulletins