NULL pointer dereference in Junos OS Evolved and Juniper Junos OS - CVE-2022-22233

 

NULL pointer dereference in Junos OS Evolved and Juniper Junos OS - CVE-2022-22233

Published: October 21, 2022


Vulnerability identifier: #VU68570
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-22233
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Junos OS Evolved
Juniper Junos OS
Software vendor:
Juniper Networks, Inc.

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in the Routing Protocol Daemon (rpd) caused by the Area Border Router (ABR) leaking the SRMS entries having "S" flag set from IS-IS Level 2 to Level 1. A local user can execute certain CLI commands and crash the daemon.

Successful vulnerability exploitation requires Segment Routing (SR) to Label Distribution Protocol (LDP) interworking scenario, when router is configured with Segment Routing Mapping Server (SRMS) at any node.


Remediation

Install update from vendor's website.

External links