CVE-2022-22214: Junos OS and Junos OS Evolved: In an MPLS scenario upon receipt of a specific IPv6 packet an FPC will crash
An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent attacker to cause a PFE crash and thereby a Denial of Service (DoS). An FPC will crash and reboot after receiving a specific transit IPv6 packet over MPLS. Continued receipt of this packet will create a sustained Denial of Service (DoS) condition. This issue does not affect systems configured for IPv4 only. This issue affects: Juniper Networks Junos OS All versions prior to 12.3R12-S21; 15.1 versions prior to 15.1R7-S10; 17.3 versions prior to 17.3R3-S12; 18.3 versions prior to 18.3R3-S6; 18.4 versions prior to 18.4R2-S9, 18.4R3-S9; 19.1 versions prior to 19.1R2-S3, 19.1R3-S7; 19.2 versions prior to 19.2R1-S7, 19.2R3-S3; 19.3 versions prior to 19.3R2-S7, 19.3R3-S4; 19.4 versions prior to 19.4R3-S5; 20.1 versions prior to 20.1R3; 20.2 versions prior to 20.2R3-S2; 20.3 versions prior to 20.3R3; 20.4 versions prior to 20.4R2-S2, 20.4R3; 21.1 versions prior to 21.1R2. Juniper Networks Junos OS Evolved All versions prior to 20.4R3-S3-EVO; 21.2 versions prior to 21.2R3-EVO; 21.3 versions prior to 21.3R2-S1-EVO, 21.3R3-EVO; 21.4 versions prior to 21.4R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22214?
The severity of CVE-2022-22214 is classified as high due to its potential to cause a Denial of Service (DoS).
How do I fix CVE-2022-22214?
To fix CVE-2022-22214, update the Junos OS and Junos OS Evolved to the recommended patched versions provided by Juniper Networks.
What systems are affected by CVE-2022-22214?
CVE-2022-22214 affects various versions of Juniper Networks Junos OS and Junos OS Evolved, particularly those prior to the patched updates.
What can an attacker achieve with CVE-2022-22214?
An attacker can exploit CVE-2022-22214 to crash the Packet Forwarding Engine (PFE), resulting in a Denial of Service condition.
Is there a workaround for CVE-2022-22214?
There is no official workaround for CVE-2022-22214, and the best approach is to apply the necessary software updates as soon as possible.