NULL pointer dereference in Junos OS Evolved and Juniper Junos OS - CVE-2022-22233
Published: October 21, 2022
Junos OS Evolved
Juniper Junos OS
Juniper Networks, Inc.
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the Routing Protocol Daemon (rpd) caused by the Area Border Router (ABR) leaking the SRMS entries having "S" flag set from IS-IS Level 2 to Level 1. A local user can execute certain CLI commands and crash the daemon.
Successful vulnerability exploitation requires Segment Routing (SR) to Label Distribution Protocol (LDP) interworking scenario, when router is configured with Segment Routing Mapping Server (SRMS) at any node.