PT-2022-15297 · Juniper Networks · Junos

Published

2022-10-18

·

Updated

2023-06-27

·

CVE-2022-22231

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Junos OS versions prior to 21.4R1-S2 Junos OS version 21.4R2 on SRX Series
Description The issue is related to an Unchecked Return Value to NULL Pointer Dereference in the Packet Forwarding Engine of Junos OS, allowing an unauthenticated network-based attacker to cause a Denial of Service. Specifically, on SRX Series, if Unified Threat Management Enhanced Content Filtering and AntiVirus are enabled together and the system processes certain valid transit traffic, the Packet Forwarding Engine will crash and restart.
Recommendations For Junos OS versions prior to 21.4R1-S2, update to version 21.4R1-S2 or later. For Junos OS version 21.4R2 on SRX Series, consider disabling Unified Threat Management Enhanced Content Filtering and AntiVirus together until a patch is available.

Fix

DoS

Unchecked Return Value

Weakness Enumeration

Related Identifiers

CVE-2022-22231

Affected Products

Junos