CVE-2022-22168: Junos OS: vMX and MX150: Specific packets might cause a memory leak and eventually an FPC reboot
An Improper Validation of Specified Type of Input vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated adjacent attacker to trigger a Missing Release of Memory after Effective Lifetime vulnerability. Continued exploitation of this vulnerability will eventually lead to an FPC reboot and thereby a Denial of Service (DoS). This issue affects: Juniper Networks Junos OS on vMX and MX150: All versions prior to 19.2R1-S8, 19.2R3-S4; 19.3 versions prior to 19.3R3-S5; 19.4 versions prior to 19.4R2-S5, 19.4R3-S6; 20.1 versions prior to 20.1R3-S2; 20.2 versions prior to 20.2R3-S3; 20.3 versions prior to 20.3R3-S1; 20.4 versions prior to 20.4R3; 21.1 versions prior to 21.1R2-S1, 21.1R3; 21.2 versions prior to 21.2R1-S1, 21.2R2; 21.3 versions prior to 21.3R1-S1, 21.3R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-22168.
What is the severity level of CVE-2022-22168?
The severity level of CVE-2022-22168 is medium with a CVSS score of 6.5.
How can an unauthenticated adjacent attacker exploit CVE-2022-22168?
An unauthenticated adjacent attacker can exploit CVE-2022-22168 to trigger a Missing Release of Memory after Effective Lifetime vulnerability.
Is Juniper Networks Junos OS affected by CVE-2022-22168?
Yes, Juniper Networks Junos OS is affected by CVE-2022-22168.
Where can I find more information about CVE-2022-22168?
You can find more information about CVE-2022-22168 at the Juniper Networks security advisory page.