PT-2022-15297 · Juniper Networks · Junos
Published
2022-10-18
·
Updated
2023-06-27
·
CVE-2022-22231
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Junos OS versions prior to 21.4R1-S2
Junos OS version 21.4R2 on SRX Series
Description
The issue is related to an Unchecked Return Value to NULL Pointer Dereference in the Packet Forwarding Engine of Junos OS, allowing an unauthenticated network-based attacker to cause a Denial of Service. Specifically, on SRX Series, if Unified Threat Management Enhanced Content Filtering and AntiVirus are enabled together and the system processes certain valid transit traffic, the Packet Forwarding Engine will crash and restart.
Recommendations
For Junos OS versions prior to 21.4R1-S2, update to version 21.4R1-S2 or later.
For Junos OS version 21.4R2 on SRX Series, consider disabling Unified Threat Management Enhanced Content Filtering and AntiVirus together until a patch is available.
Fix
DoS
Unchecked Return Value
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Junos