CVE-2022-22211: Junos OS Evolved: PTX Series: Multiple FPCs become unreachable due to continuous polling of specific SNMP OID

Published Oct 18, 2022
·
Updated

A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved on PTX Series allows an unprivileged attacker to cause Denial of Service (DoS). Continuously polling the SNMP jnxCosQstatTable causes the FPC to run out of GUID space, causing a Denial of Service to the FPC resources. When the FPC runs out of the GUID space, you will see the following syslog messages. The evo-aftmand-bt process is asserting. fpc1 evo-aftmand-bt[17556]: %USER-3: getnextguid: Ran out of Guid Space start 1748051689472 end 1752346656767 fpc1 audit[17556]: %AUTH-5: ANOMABEND auid=4294967295 uid=0 gid=0 ses=4294967295 pid=17556 comm="EvoAftManBt-mai" exe="/usr/sbin/evo-aftmand-bt" sig=6 fpc1 kernel: %KERN-5: audit: type=1701 audit(1648567505.119:57): auid=4294967295 uid=0 gid=0 ses=4294967295 pid=17556 comm="EvoAftManBt-mai" exe="/usr/sbin/evo-aftmand-bt" sig=6 fpc1 emfd-fpa[14438]: %USER-5: Alarm set: APP color=red, class=CHASSIS, reason=Application evo-aftmand-bt fail on node Fpc1 fpc1 emfd-fpa[14438]: %USER-3-EMFFPAALARMREP: RaiseAlarm: Alarm(Location: /Chassis[0]/Fpc[1] Module: sysman Object: evo-aftmand-bt:0 Error: 2) reported fpc1 sysepochman[12738]: %USER-5-SYSTEMREBOOTEVENT: Reboot [node] [ungraceful reboot] [evo-aftmand-bt exited] The FPC resources can be monitored using the following commands: user@router> start shell [vrf:none] user@router-re0:~$ cli -c "show platform application-info allocations app evo-aftmand-bt" | grep ^fpc | grep -v Route | grep -i -v Nexthop | awk '{total[$1] += $5} END { for (key in total) { print key " " total[key]/4294967296 }}' Once the FPCs become unreachable they must be manually restarted as they do not self-recover. This issue affects Juniper Networks Junos OS Evolved on PTX Series: All versions prior to 20.4R3-S4-EVO; 21.1-EVO version 21.1R1-EVO and later versions; 21.2-EVO version 21.2R1-EVO and later versions; 21.3-EVO versions prior to 21.3R3-EVO; 21.4-EVO versions prior to 21.4R2-EVO; 22.1-EVO versions prior to 22.1R2-EVO.

Affected Software

57 affected components
Juniper Junos OS Evolved<20.4
Juniper Junos OS Evolved=20.4
Juniper Junos OS Evolved=20.4-r1
Juniper Junos OS Evolved=20.4-r1-s1
Juniper Junos OS Evolved=20.4-r1-s2
Juniper Junos OS Evolved=20.4-r2
Juniper Junos OS Evolved=20.4-r2-s1
Juniper Junos OS Evolved=20.4-r2-s2
Juniper Junos OS Evolved=20.4-r2-s3
Juniper Junos OS Evolved=20.4-r3
Juniper Junos OS Evolved=20.4-r3-s1
Juniper Junos OS Evolved=20.4-r3-s2
Juniper Junos OS Evolved=20.4-r3-s3
Juniper Junos OS Evolved=21.1
Juniper Junos OS Evolved=21.1-r1
Juniper Junos OS Evolved=21.1-r1-s1
Juniper Junos OS Evolved=21.1-r2
Juniper Junos OS Evolved=21.1-r3
Juniper Junos OS Evolved=21.1-r3-s1
Juniper Junos OS Evolved=21.2
Juniper Junos OS Evolved=21.2-r1
Juniper Junos OS Evolved=21.2-r1-s1
Juniper Junos OS Evolved=21.2-r1-s2
Juniper Junos OS Evolved=21.2-r2
Juniper Junos OS Evolved=21.2-r2-s1
Juniper Junos OS Evolved=21.2-r2-s2
Juniper Junos OS Evolved=21.2-r3
Juniper Junos OS Evolved=21.3
Juniper Junos OS Evolved=21.3-r1
Juniper Junos OS Evolved=21.3-r1-s1
Juniper Junos OS Evolved=21.3-r2
Juniper Junos OS Evolved=21.3-r2-s1
Juniper Junos OS Evolved=21.3-r2-s2
Juniper Junos OS Evolved=21.4
Juniper Junos OS Evolved=21.4-r1
Juniper Junos OS Evolved=21.4-r1-s1
Juniper Junos OS Evolved=21.4-r1-s2
Juniper Junos OS Evolved=22.1-r1
Juniper Junos OS Evolved=22.1-r1-s1
Juniper Junos OS Evolved=22.1-r1-s2
Juniper PTX1000
Juniper Ptx1000-72q
Juniper PTX10000
Juniper PTX10001
Juniper PTX10001-36MR
Juniper PTX100016
Juniper PTX10002
Juniper PTX10002-60C
Juniper PTX10003
Juniper Ptx10003 160c
Juniper Ptx10003 80c
Juniper Ptx10003 81cd
Juniper PTX10004
Juniper PTX10008
Juniper PTX10016
Juniper PTX3000
Juniper PTX5000

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Juniper Networks Junos OS Evolved on PTX Series to a version that resolves this vulnerability.

    Fixed in 20.4R3-S4-EVO
  2. Upgrade

    Upgrade Juniper Networks Junos OS Evolved on PTX Series to a version that resolves this vulnerability.

    Fixed in 21.3R3-EVO
  3. Upgrade

    Upgrade Juniper Networks Junos OS Evolved on PTX Series to a version that resolves this vulnerability.

    Fixed in 21.4R2-EVO
  4. Upgrade

    Upgrade Juniper Networks Junos OS Evolved on PTX Series to a version that resolves this vulnerability.

    Fixed in 22.1R2-EVO
  5. Upgrade

    Upgrade Juniper Networks Junos OS Evolved on PTX Series to a version that resolves this vulnerability.

    Fixed in 22.2R1-EVO
  6. Operational

    After upgrading, if any FPC resources become unreachable (including those caused by continuous polling of specific SNMP OIDs), manually restart the affected FPCs because they do not self-recover.

Event History

Oct 18, 2022
CVE Published
via MITRE·02:46 AM
Data Sourced
via MITRE·02:46 AM
RemedyDescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-22211 vulnerability?

CVE-2022-22211 is a limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved on PTX Series that allows an unprivileged attacker to cause Denial of Service (DoS) by continuously polling the SNMP jnxCosQstatTable.

2

How to fix CVE-2022-22211 vulnerability?

To fix CVE-2022-22211 vulnerability, Juniper Networks has released security advisories along with patches and updates. It is recommended to apply the necessary patches as soon as possible.

3

What is the severity of CVE-2022-22211 vulnerability?

The severity of CVE-2022-22211 vulnerability is rated as high with a CVSS score of 7.5.

4

Is Juniper Ptx Series affected by CVE-2022-22211 vulnerability?

No, Juniper Ptx Series devices are not vulnerable to the CVE-2022-22211 vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203