#VU65372 Resource exhaustion in Juniper Junos OS and Junos OS Evolved - CVE-2022-22215
Published: July 16, 2022
Juniper Junos OS
Junos OS Evolved
Juniper Networks, Inc.
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to failure to release file descriptors (e.g. delete the "respective/var/run/.env" file) in plugable authentication module (PAM) when handling gRPC connection termination events. A remote attacker can trigger inode exhaustion by initiating and terminating a large number of gRPC connections and perform a denial of service (DoS) attack.