CVE-2022-22167: Junos OS: SRX Series: If no-syn-check is enabled, traffic classified as UNKNOWN gets permitted by pre-id-default-policy

Published Jan 19, 2022
·
Updated

A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when 'no-syn-check' is enabled on the device. While JDPI correctly classifies out-of-state asymmetric TCP flows as the dynamic-application UNKNOWN, this classification is not provided to the policy module properly and hence traffic continues to use the pre-id-default-policy, which is more permissive, causing the firewall to allow traffic to be forwarded that should have been denied. This issue only occurs when 'set security flow tcp-session no-syn-check' is configured on the device. This issue affects Juniper Networks Junos OS on SRX Series: 18.4 versions prior to 18.4R2-S10, 18.4R3-S10; 19.1 versions prior to 19.1R3-S8; 19.2 versions prior to 19.2R1-S8, 19.2R3-S4; 19.3 versions prior to 19.3R3-S3; 19.4 versions prior to 19.4R3-S5; 20.1 versions prior to 20.1R3-S1; 20.2 versions prior to 20.2R3-S2; 20.3 versions prior to 20.3R3-S1; 20.4 versions prior to 20.4R2-S2, 20.4R3; 21.1 versions prior to 21.1R2-S2, 21.1R3; 21.2 versions prior to 21.2R2. This issue does not affect Juniper Networks Junos OS versions prior to 18.4R1.

Affected Software

160 affected components
Juniper Junos=18.4
Juniper Junos=18.4-r1
Juniper Junos=18.4-r1-s1
Juniper Junos=18.4-r1-s2
Juniper Junos=18.4-r1-s3
Juniper Junos=18.4-r1-s4
Juniper Junos=18.4-r1-s5
Juniper Junos=18.4-r1-s6
Juniper Junos=18.4-r1-s7
Juniper Junos=18.4-r2
Juniper Junos=18.4-r2-s1
Juniper Junos=18.4-r2-s2
Juniper Junos=18.4-r2-s3
Juniper Junos=18.4-r2-s4
Juniper Junos=18.4-r2-s5
Juniper Junos=18.4-r2-s6
Juniper Junos=18.4-r2-s7
Juniper Junos=18.4-r2-s8
Juniper Junos=18.4-r2-s9
Juniper Junos=18.4-r3
Juniper Junos=18.4-r3-s1
Juniper Junos=18.4-r3-s2
Juniper Junos=18.4-r3-s3
Juniper Junos=18.4-r3-s4
Juniper Junos=18.4-r3-s5
Juniper Junos=18.4-r3-s6
Juniper Junos=18.4-r3-s7
Juniper Junos=18.4-r3-s8
Juniper Junos=18.4-r3-s9
Juniper Junos=19.1
Juniper Junos=19.1-r1
Juniper Junos=19.1-r1-s1
Juniper Junos=19.1-r1-s2
Juniper Junos=19.1-r1-s3
Juniper Junos=19.1-r1-s4
Juniper Junos=19.1-r1-s5
Juniper Junos=19.1-r1-s6
Juniper Junos=19.1-r2
Juniper Junos=19.1-r2-s1
Juniper Junos=19.1-r2-s2
Juniper Junos=19.1-r2-s3
Juniper Junos=19.1-r3
Juniper Junos=19.1-r3-s1
Juniper Junos=19.1-r3-s2
Juniper Junos=19.1-r3-s3
Juniper Junos=19.1-r3-s4
Juniper Junos=19.1-r3-s5
Juniper Junos=19.1-r3-s6
Juniper Junos=19.1-r3-s7
Juniper Junos=19.2
Juniper Junos=19.2-r1
Juniper Junos=19.2-r1-s1
Juniper Junos=19.2-r1-s2
Juniper Junos=19.2-r1-s3
Juniper Junos=19.2-r1-s4
Juniper Junos=19.2-r1-s5
Juniper Junos=19.2-r1-s6
Juniper Junos=19.2-r1-s7
Juniper Junos=19.2-r3
Juniper Junos=19.2-r3-s1
Juniper Junos=19.2-r3-s2
Juniper Junos=19.2-r3-s3
Juniper Junos=19.3
Juniper Junos=19.3-r1
Juniper Junos=19.3-r1-s1
Juniper Junos=19.3-r2
Juniper Junos=19.3-r2-s1
Juniper Junos=19.3-r2-s2
Juniper Junos=19.3-r2-s3
Juniper Junos=19.3-r2-s4
Juniper Junos=19.3-r2-s5
Juniper Junos=19.3-r2-s6
Juniper Junos=19.3-r3
Juniper Junos=19.3-r3-s1
Juniper Junos=19.3-r3-s2
Juniper Junos=19.4
Juniper Junos=19.4-r1
Juniper Junos=19.4-r1-s1
Juniper Junos=19.4-r1-s2
Juniper Junos=19.4-r1-s3
Juniper Junos=19.4-r1-s4
Juniper Junos=19.4-r2
Juniper Junos=19.4-r2-s1
Juniper Junos=19.4-r2-s2
Juniper Junos=19.4-r2-s3
Juniper Junos=19.4-r2-s4
Juniper Junos=19.4-r2-s5
Juniper Junos=19.4-r3
Juniper Junos=19.4-r3-s1
Juniper Junos=19.4-r3-s2
Juniper Junos=19.4-r3-s3
Juniper Junos=19.4-r3-s4
Juniper Junos=20.1
Juniper Junos=20.1-r1
Juniper Junos=20.1-r1-s1
Juniper Junos=20.1-r1-s2
Juniper Junos=20.1-r1-s3
Juniper Junos=20.1-r1-s4
Juniper Junos=20.1-r2
Juniper Junos=20.1-r2-s1
Juniper Junos=20.1-r2-s2
Juniper Junos=20.1-r3
Juniper Junos=20.2
Juniper Junos=20.2-r1
Juniper Junos=20.2-r1-s1
Juniper Junos=20.2-r1-s2
Juniper Junos=20.2-r1-s3
Juniper Junos=20.2-r2
Juniper Junos=20.2-r2-s1
Juniper Junos=20.2-r2-s2
Juniper Junos=20.2-r2-s3
Juniper Junos=20.2-r3
Juniper Junos=20.2-r3-s1
Juniper Junos=20.3
Juniper Junos=20.3-r1
Juniper Junos=20.3-r1-s1
Juniper Junos=20.3-r2
Juniper Junos=20.3-r2-s1
Juniper Junos=20.3-r3
Juniper Junos=20.4
Juniper Junos=20.4-r1
Juniper Junos=20.4-r1-s1
Juniper Junos=20.4-r2
Juniper Junos=20.4-r2-s1
Juniper Junos=21.1
Juniper Junos=21.1-r1
Juniper Junos=21.1-r1-s1
Juniper Junos=21.1-r2
Juniper Junos=21.1-r2-s1
Juniper Junos=21.2
Juniper Junos=21.2-r1
Juniper Junos=21.2-r1-s1
Juniper Junos=21.2-r1-s2
Juniper SRX100
Juniper SRX110
Juniper SRX1400
Juniper SRX1500
Juniper SRX210
Juniper SRX220
Juniper SRX240
Juniper Srx240h2
Juniper SRX300
Juniper SRX320
Juniper SRX340
Juniper SRX3400
Juniper SRX345
Juniper SRX3600
Juniper Srx380
Juniper SRX4000
Juniper SRX4100
Juniper SRX4200
Juniper SRX4600
Juniper SRX5000
Juniper SRX5400
Juniper SRX550
Juniper Srx550 Hm
Juniper SRX550m
Juniper SRX5600
Juniper SRX5800
Juniper SRX650

Remediation

Information

The following software releases have been updated to resolve this specific issue: 18.4R2-S10, 18.4R3-S10, 19.1R3-S8, 19.2R1-S8, 19.2R3-S4, 19.3R3-S3, 19.4R3-S5, 20.1R3-S1, 20.2R3-S2, 20.3R3-S1, 20.4R2-S2, 20.4R3, 21.1R2-S2, 21.1R3, 21.2R2, 21.3R1, and all subsequent releases.

Event History

Jan 19, 2022
CVE Published
via MITRE·12:21 AM
Data Sourced
via MITRE·12:21 AM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2022-22167?

The severity of CVE-2022-22167 is currently classified as high due to its potential to allow unauthorized access to networks.

2

How do I fix CVE-2022-22167?

To fix CVE-2022-22167, it is recommended to disable the 'no-syn-check' option if it is currently enabled.

3

Which versions of Junos OS are affected by CVE-2022-22167?

CVE-2022-22167 affects Junos OS versions 18.4, 19.1, 19.2, 19.3, 19.4, 20.1, 20.2, and 20.3.

4

Can CVE-2022-22167 compromise my network security?

Yes, CVE-2022-22167 can compromise network security by potentially allowing attackers to bypass Deep Packet Inspection rules.

5

Is there a patch available for CVE-2022-22167?

Yes, patches have been released for affected versions of Junos OS to mitigate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203