PT-2022-6677 · Juniper Networks · Junos+1

Published

2022-10-12

·

Updated

2023-06-27

·

CVE-2022-22233

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS versions prior to 21.4R1-S2, 21.4R2-S1, 21.4R3 Juniper Networks Junos OS versions 21.4 through 22.1 prior to 22.1R2 Juniper Networks Junos OS Evolved versions prior to 21.4R1-S2-EVO, 21.4R2-S1-EVO, 21.4R3-EVO Juniper Networks Junos OS Evolved versions 21.4-EVO through 22.1-EVO prior to 22.1R2-EVO
Description The issue is related to an Unchecked Return Value to NULL Pointer Dereference vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved. This vulnerability can be exploited by a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). The vulnerability is observed in a Segment Routing (SR) to Label Distribution Protocol (LDP) interworking scenario when an Area Border Router (ABR) leaks specific entries from IS-IS Level 2 to Level 1 and a low-privileged CLI command is issued.
Recommendations For Juniper Networks Junos OS versions prior to 21.4R1-S2, 21.4R2-S1, 21.4R3, update to 21.4R1-S2, 21.4R2-S1, or 21.4R3. For Juniper Networks Junos OS versions 21.4 through 22.1 prior to 22.1R2, update to 22.1R2. For Juniper Networks Junos OS Evolved versions prior to 21.4R1-S2-EVO, 21.4R2-S1-EVO, 21.4R3-EVO, update to 21.4R1-S2-EVO, 21.4R2-S1-EVO, or 21.4R3-EVO. For Juniper Networks Junos OS Evolved versions 21.4-EVO through 22.1-EVO prior to 22.1R2-EVO, update to 22.1R2-EVO.

Fix

DoS

Unchecked Return Value

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2023-03318
CVE-2022-22233

Affected Products

Junos
Junos Evolved