PT-2022-6677 · Juniper Networks · Junos+1
Published
2022-10-12
·
Updated
2023-06-27
·
CVE-2022-22233
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS versions prior to 21.4R1-S2, 21.4R2-S1, 21.4R3
Juniper Networks Junos OS versions 21.4 through 22.1 prior to 22.1R2
Juniper Networks Junos OS Evolved versions prior to 21.4R1-S2-EVO, 21.4R2-S1-EVO, 21.4R3-EVO
Juniper Networks Junos OS Evolved versions 21.4-EVO through 22.1-EVO prior to 22.1R2-EVO
Description
The issue is related to an Unchecked Return Value to NULL Pointer Dereference vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved. This vulnerability can be exploited by a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). The vulnerability is observed in a Segment Routing (SR) to Label Distribution Protocol (LDP) interworking scenario when an Area Border Router (ABR) leaks specific entries from IS-IS Level 2 to Level 1 and a low-privileged CLI command is issued.
Recommendations
For Juniper Networks Junos OS versions prior to 21.4R1-S2, 21.4R2-S1, 21.4R3, update to 21.4R1-S2, 21.4R2-S1, or 21.4R3.
For Juniper Networks Junos OS versions 21.4 through 22.1 prior to 22.1R2, update to 22.1R2.
For Juniper Networks Junos OS Evolved versions prior to 21.4R1-S2-EVO, 21.4R2-S1-EVO, 21.4R3-EVO, update to 21.4R1-S2-EVO, 21.4R2-S1-EVO, or 21.4R3-EVO.
For Juniper Networks Junos OS Evolved versions 21.4-EVO through 22.1-EVO prior to 22.1R2-EVO, update to 22.1R2-EVO.
Fix
DoS
Unchecked Return Value
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Junos
Junos Evolved