#VU68328 Improper handling of exceptional conditions in Junos OS Evolved - CVE-2022-22227

 

#VU68328 Improper handling of exceptional conditions in Junos OS Evolved - CVE-2022-22227

Published: October 14, 2022


Vulnerability identifier: #VU68328
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-22227
CWE-ID: CWE-755
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Junos OS Evolved
Software vendor:
Juniper Networks, Inc.

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper handling of errors in the Packet Forwarding Engine (PFE) when processing IPv6 transit traffic. A remote attacker can send specially crafted input through the device and cause increased CPU utilization, which can result in denial of service (DoS).


Remediation

Install updates from vendor's website.

External links