#VU68365 Input validation error in Junos OS Evolved and Juniper Junos OS - CVE-2022-22230

 

#VU68365 Input validation error in Junos OS Evolved and Juniper Junos OS - CVE-2022-22230

Published: October 17, 2022


Vulnerability identifier: #VU68365
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-22230
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Junos OS Evolved
Juniper Junos OS
Software vendor:
Juniper Networks, Inc.

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the Routing Protocol Daemon (rpd). If another router generates more than one specific valid OSPFv3 LSA then rpd will crash.


Remediation

Install updates from vendor's website.

External links