CVE-2022-22198: Junos OS: MX MS-MPC or MS-MIC, or SRX SPC crashes if it receives a SIP message with a specific contact header format
An Access of Uninitialized Pointer vulnerability in the SIP ALG of Juniper Networks Junos OS allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Continued receipt of these specific packets will cause a sustained Denial of Service condition. On all MX and SRX platforms, if the SIP ALG is enabled, an MS-MPC or MS-MIC, or SPC will crash if it receives a SIP message with a specific contact header format. This issue affects Juniper Networks Junos OS on MX Series and SRX Series: 20.4 versions prior to 20.4R3; 21.1 versions prior to 21.1R2-S1, 21.1R3; 21.2 versions prior to 21.2R2. This issue does not affect versions prior to 20.4R1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-22198.
What is the severity of CVE-2022-22198?
The severity of CVE-2022-22198 is high with a score of 7.5.
What is the affected software for CVE-2022-22198?
The affected software for CVE-2022-22198 is Juniper Networks Junos OS versions 20.4-r1, 20.4-r1-s1, 20.4-r2, 20.4-r2-s1, 20.4-r2-s2, 21.1-r1, 21.1-r1-s1, 21.1-r2, 21.2-r1, 21.2-r1-s1, and 21.2-r1-s2.
What is the impact of this vulnerability?
This vulnerability allows an unauthenticated network-based attacker to cause a Denial of Service (DoS) by sending specific packets, leading to a sustained DoS condition.
How can I fix CVE-2022-22198?
To fix CVE-2022-22198, it is recommended to update to the latest version of Juniper Networks Junos OS.