NULL pointer dereference in Junos OS and Junos OS Evolved - CVE-2022-22233

 

NULL pointer dereference in Junos OS and Junos OS Evolved - CVE-2022-22233

Published: October 21, 2022


Vulnerability identifier: #VU68570
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22233
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in the Routing Protocol Daemon (rpd) caused by the Area Border Router (ABR) leaking the SRMS entries having "S" flag set from IS-IS Level 2 to Level 1. A local user can execute certain CLI commands and crash the daemon.

Successful vulnerability exploitation requires Segment Routing (SR) to Label Distribution Protocol (LDP) interworking scenario, when router is configured with Segment Routing Mapping Server (SRMS) at any node.


Affected software

Junos OS
Junos OS Evolved

How to mitigate CVE-2022-22233

Install update from vendor's website.

Junos OS - addressed in versions 21.4R1-S2, 21.4R2-S1, 21.4R3, 22.1R2, 22.2R1
Junos OS Evolved - addressed in versions 21.4R1-S2-EVO, 21.4R2-S1-EVO, 21.4R3-EVO, 22.1R2-EVO, 22.2R1-EVO

External References

Related Security Bulletins