PT-2022-6706 · Juniper Networks · Junos Evolved

Published

2022-04-13

·

Updated

2022-04-21

·

CVE-2022-22195

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS Evolved versions prior to 20.4R3-S1-EVO Juniper Networks Junos OS Evolved version 21.1 versions prior to 21.1R3-EVO Juniper Networks Junos OS Evolved version 21.2 versions prior to 21.2R3-EVO Juniper Networks Junos OS Evolved version 21.3 versions prior to 21.3R2-EVO
Description The issue is related to an Improper Update of Reference Count vulnerability in the kernel of Juniper Networks Junos OS Evolved. This vulnerability allows an unauthenticated, network-based attacker to trigger a counter overflow, eventually causing a Denial of Service (DoS).
Recommendations For versions prior to 20.4R3-S1-EVO, update to 20.4R3-S1-EVO or later. For version 21.1, update to 21.1R3-EVO or later. For version 21.2, update to 21.2R3-EVO or later. For version 21.3, update to 21.3R2-EVO or later. As a temporary workaround, consider restricting network access to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03564
CVE-2022-22195

Affected Products

Junos Evolved