CVE-2022-22175: Junos OS: MX Series and SRX Series: The flowd daemon will crash if the SIP ALG is enabled and specific SIP messages are processed
An Improper Locking vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated networked attacker to cause a flowprocessing daemon (flowd) crash and thereby a Denial of Service (DoS). Continued receipt of these specific packets will cause a sustained Denial of Service condition. This issue can occur in a scenario where the SIP ALG is enabled and specific SIP messages are being processed simultaneously. This issue affects: Juniper Networks Junos OS on MX Series and SRX Series 20.4 versions prior to 20.4R3-S1; 21.1 versions prior to 21.1R2-S2, 21.1R3; 21.2 versions prior to 21.2R1-S2, 21.2R2; 21.3 versions prior to 21.3R1-S1, 21.3R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-22175.
What is the severity of CVE-2022-22175?
The severity of CVE-2022-22175 is high with a CVSS score of 7.5.
How does CVE-2022-22175 affect Juniper Networks Junos OS?
CVE-2022-22175 affects Juniper Networks Junos OS on MX Series and SRX Series.
How can an attacker exploit CVE-2022-22175?
An unauthenticated networked attacker can exploit CVE-2022-22175 by causing a flowprocessing daemon crash in the SIP ALG, leading to a Denial of Service (DoS).
How can I fix CVE-2022-22175?
To fix CVE-2022-22175, it is recommended to upgrade to a fixed version of Juniper Networks Junos OS.