CVE-2022-22188: Junos OS: QFX5100/QFX5110/QFX5120/QFX5200/QFX5210/EX4600/EX4650 Series: When storm control profiling is enabled and a device is under an active storm, a Heap-based Buffer Overflow in the PFE will cause a device to hang.
An Uncontrolled Memory Allocation vulnerability leading to a Heap-based Buffer Overflow in the packet forwarding engine (PFE) of Juniper Networks Junos OS allows a network-based unauthenticated attacker to flood the device with traffic leading to a Denial of Service (DoS). The device must be configured with storm control profiling limiting the number of unknown broadcast, multicast, or unicast traffic to be vulnerable to this issue. This issue affects: Juniper Networks Junos OS on QFX5100/QFX5110/QFX5120/QFX5200/QFX5210/EX4600/EX4650 Series; 20.2 version 20.2R1 and later versions prior to 20.2R2. This issue does not affect: Juniper Networks Junos OS versions prior to 20.2R1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-22188?
CVE-2022-22188 is an Uncontrolled Memory Allocation vulnerability leading to a Heap-based Buffer Overflow in the packet forwarding engine (PFE) of Juniper Networks Junos OS.
How does CVE-2022-22188 affect Juniper Junos OS?
CVE-2022-22188 allows a network-based unauthenticated attacker to flood the device with traffic leading to a Denial of Service (DoS) on Juniper Junos OS.
How severe is CVE-2022-22188?
CVE-2022-22188 has a severity rating of 7.5 (High).
How can I fix CVE-2022-22188?
To fix CVE-2022-22188, update Juniper Junos OS to the latest version provided by Juniper Networks.
Where can I find more information about CVE-2022-22188?
More information about CVE-2022-22188 can be found in the Juniper Networks security advisory at this link: https://kb.juniper.net/JSA69497