Input validation error in Junos OS and Junos OS Evolved - CVE-2022-22230

 

Input validation error in Junos OS and Junos OS Evolved - CVE-2022-22230

Published: October 17, 2022


Vulnerability identifier: #VU68365
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22230
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the Routing Protocol Daemon (rpd). If another router generates more than one specific valid OSPFv3 LSA then rpd will crash.


Affected software

Junos OS
Junos OS Evolved

How to mitigate CVE-2022-22230

Install updates from vendor's website.

Junos OS - addressed in versions 19.2R3-S6, 19.4R2-S8, 19.4R3-S9, 20.2R3-S5, 20.3R3-S5, 20.4R3-S4, 21.1R3-S2, 21.2R3-S1, 21.3R3-S2, 21.4R2, 22.1R2, 22.3R1
Junos OS Evolved - addressed in versions 20.4R3-S5-EVO, 21.1R3-S2-EVO, 21.2R3-S1-EVO, 21.3R3-S2-EVO, 21.4R2-EVO, 22.1R2-EVO, 22.2R2-EVO, 22.3R1-EVO

External References

Related Security Bulletins