First published: Tue Oct 18 2022(Updated: )
An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). On SRX5000 Series with SPC3, SRX4000 Series, and vSRX, when PowerMode IPsec is configured and a malformed ESP packet matching an established IPsec tunnel is received the PFE crashes. This issue affects Juniper Networks Junos OS on SRX5000 Series with SPC3, SRX4000 Series, and vSRX: All versions prior to 19.4R2-S6, 19.4R3-S7; 20.1 versions prior to 20.1R3-S3; 20.2 versions prior to 20.2R3-S4; 20.3 versions prior to 20.3R3-S3; 20.4 versions prior to 20.4R3-S2; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R3; 21.3 versions prior to 21.3R1-S2, 21.3R2.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper Junos | <19.4 | |
Juniper Junos | =19.4 | |
Juniper Junos | =19.4-r1 | |
Juniper Junos | =19.4-r1-s1 | |
Juniper Junos | =19.4-r1-s2 | |
Juniper Junos | =19.4-r1-s3 | |
Juniper Junos | =19.4-r1-s4 | |
Juniper Junos | =19.4-r2 | |
Juniper Junos | =19.4-r2-s1 | |
Juniper Junos | =19.4-r2-s2 | |
Juniper Junos | =19.4-r2-s3 | |
Juniper Junos | =19.4-r2-s4 | |
Juniper Junos | =19.4-r2-s5 | |
Juniper Junos | =19.4-r3-s7 | |
Juniper Junos | =20.1 | |
Juniper Junos | =20.1-r1 | |
Juniper Junos | =20.1-r1-s1 | |
Juniper Junos | =20.1-r1-s2 | |
Juniper Junos | =20.1-r1-s3 | |
Juniper Junos | =20.1-r1-s4 | |
Juniper Junos | =20.1-r2 | |
Juniper Junos | =20.1-r2-s1 | |
Juniper Junos | =20.1-r2-s2 | |
Juniper Junos | =20.1-r3 | |
Juniper Junos | =20.1-r3-s1 | |
Juniper Junos | =20.1-r3-s2 | |
Juniper Junos | =20.2 | |
Juniper Junos | =20.2-r1 | |
Juniper Junos | =20.2-r1-s1 | |
Juniper Junos | =20.2-r1-s2 | |
Juniper Junos | =20.2-r1-s3 | |
Juniper Junos | =20.2-r2 | |
Juniper Junos | =20.2-r2-s1 | |
Juniper Junos | =20.2-r2-s2 | |
Juniper Junos | =20.2-r2-s3 | |
Juniper Junos | =20.2-r3 | |
Juniper Junos | =20.2-r3-s1 | |
Juniper Junos | =20.2-r3-s2 | |
Juniper Junos | =20.2-r3-s3 | |
Juniper Junos | =20.3 | |
Juniper Junos | =20.3-r1 | |
Juniper Junos | =20.3-r1-s1 | |
Juniper Junos | =20.3-r1-s2 | |
Juniper Junos | =20.3-r2 | |
Juniper Junos | =20.3-r2-s1 | |
Juniper Junos | =20.3-r3 | |
Juniper Junos | =20.3-r3-s1 | |
Juniper Junos | =20.3-r3-s2 | |
Juniper Junos | =20.4 | |
Juniper Junos | =20.4-r1 | |
Juniper Junos | =20.4-r1-s1 | |
Juniper Junos | =20.4-r2 | |
Juniper Junos | =20.4-r2-s1 | |
Juniper Junos | =20.4-r2-s2 | |
Juniper Junos | =20.4-r3 | |
Juniper Junos | =20.4-r3-s1 | |
Juniper Junos | =21.1 | |
Juniper Junos | =21.1-r1 | |
Juniper Junos | =21.1-r1-s1 | |
Juniper Junos | =21.1-r2 | |
Juniper Junos | =21.1-r2-s1 | |
Juniper Junos | =21.1-r2-s2 | |
Juniper Junos | =21.2 | |
Juniper Junos | =21.2-r1 | |
Juniper Junos | =21.2-r1-s1 | |
Juniper Junos | =21.2-r1-s2 | |
Juniper Junos | =21.2-r2 | |
Juniper Junos | =21.3-r1 | |
Juniper Junos | =21.3-r1-s1 | |
Juniper Junos | =21.3-r2 | |
Juniper SRX4000 | ||
Juniper SRX4100 | ||
Juniper SRX4200 | ||
Juniper SRX4600 | ||
Junos OS SRX 5000 Series | ||
Juniper SRX5400 | ||
Juniper SRX5600 | ||
Juniper SRX5800 | ||
Juniper vSRX |
The following software releases have been updated to resolve this specific issue: 19.4R2-S6, 19.4R3-S7, 20.1R3-S3, 20.2R3-S4, 20.3R3-S3, 20.4R3-S2, 21.1R3, 21.2R3, 21.3R1-S2, 21.3R2, 21.4R1, and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22201 has been classified with a severity level that indicates it allows a Denial of Service (DoS) by an unauthenticated attacker.
You can address CVE-2022-22201 by upgrading to a patched version of Junos OS as specified in the vendor's notification.
CVE-2022-22201 affects multiple versions of Juniper Networks Junos OS, particularly on SRX5000 Series with SPC3 and SRX4000 Series devices.
Yes, CVE-2022-22201 allows an unauthenticated network-based attacker to exploit the vulnerability remotely.
The impact of CVE-2022-22201 results in a Denial of Service (DoS), causing affected systems to become unresponsive.