CVE-2022-22217: Junos OS: QFX10K Series: Denial of Service (DoS) upon receipt of crafted MLD packets on multi-homing ESI in VXLAN

Published Jul 20, 2022
·
Updated

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). The issue is caused by malformed MLD packets looping on a multi-homed Ethernet Segment Identifier (ESI) when VXLAN is configured. These MLD packets received on a multi-homed ESI are sent to the peer, and then incorrectly forwarded out the same ESI, violating the split horizon rule. This issue only affects QFX10K Series switches, including the QFX10002, QFX10008, and QFX10016. Other products and platforms are unaffected by this vulnerability. This issue affects Juniper Networks Junos OS on QFX10K Series: All versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R1-S9, 19.2R3-S5; 19.3 versions prior to 19.3R3-S6; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 versions prior to 20.1R3-S4; 20.2 versions prior to 20.2R3-S4; 20.3 versions prior to 20.3R3-S2; 20.4 versions prior to 20.4R3-S2; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R2-S1, 21.2R3; 21.3 versions prior to 21.3R2.

Affected Software

135 affected components
Juniper JUNOS<19.1
Juniper JUNOS=19.1
Juniper JUNOS=19.1-r1
Juniper JUNOS=19.1-r1-s1
Juniper JUNOS=19.1-r1-s2
Juniper JUNOS=19.1-r1-s3
Juniper JUNOS=19.1-r1-s4
Juniper JUNOS=19.1-r1-s5
Juniper JUNOS=19.1-r1-s6
Juniper JUNOS=19.1-r2
Juniper JUNOS=19.1-r2-s1
Juniper JUNOS=19.1-r2-s2
Juniper JUNOS=19.1-r2-s3
Juniper JUNOS=19.1-r3
Juniper JUNOS=19.1-r3-s1
Juniper JUNOS=19.1-r3-s2
Juniper JUNOS=19.1-r3-s3
Juniper JUNOS=19.1-r3-s4
Juniper JUNOS=19.1-r3-s5
Juniper JUNOS=19.1-r3-s6
Juniper JUNOS=19.1-r3-s7
Juniper JUNOS=19.1-r3-s8
Juniper JUNOS=19.2
Juniper JUNOS=19.2-r1
Juniper JUNOS=19.2-r1-s1
Juniper JUNOS=19.2-r1-s2
Juniper JUNOS=19.2-r1-s3
Juniper JUNOS=19.2-r1-s4
Juniper JUNOS=19.2-r1-s5
Juniper JUNOS=19.2-r1-s6
Juniper JUNOS=19.2-r1-s7
Juniper JUNOS=19.2-r1-s8
Juniper JUNOS=19.2-r2
Juniper JUNOS=19.2-r2-s1
Juniper JUNOS=19.2-r3
Juniper JUNOS=19.2-r3-s1
Juniper JUNOS=19.2-r3-s2
Juniper JUNOS=19.2-r3-s3
Juniper JUNOS=19.2-r3-s4
Juniper JUNOS=19.3
Juniper JUNOS=19.3-r1
Juniper JUNOS=19.3-r1-s1
Juniper JUNOS=19.3-r2
Juniper JUNOS=19.3-r2-s1
Juniper JUNOS=19.3-r2-s2
Juniper JUNOS=19.3-r2-s3
Juniper JUNOS=19.3-r2-s4
Juniper JUNOS=19.3-r2-s5
Juniper JUNOS=19.3-r2-s6
Juniper JUNOS=19.3-r3
Juniper JUNOS=19.3-r3-s1
Juniper JUNOS=19.3-r3-s2
Juniper JUNOS=19.3-r3-s3
Juniper JUNOS=19.3-r3-s4
Juniper JUNOS=19.3-r3-s5
Juniper JUNOS=19.4
Juniper JUNOS=19.4-r1
Juniper JUNOS=19.4-r1-s1
Juniper JUNOS=19.4-r1-s2
Juniper JUNOS=19.4-r1-s3
Juniper JUNOS=19.4-r1-s4
Juniper JUNOS=19.4-r2
Juniper JUNOS=19.4-r2-s1
Juniper JUNOS=19.4-r2-s2
Juniper JUNOS=19.4-r2-s3
Juniper JUNOS=19.4-r2-s4
Juniper JUNOS=19.4-r2-s5
Juniper JUNOS=19.4-r2-s6
Juniper JUNOS=19.4-r3
Juniper JUNOS=19.4-r3-s1
Juniper JUNOS=19.4-r3-s2
Juniper JUNOS=19.4-r3-s3
Juniper JUNOS=19.4-r3-s4
Juniper JUNOS=19.4-r3-s5
Juniper JUNOS=19.4-r3-s6
Juniper JUNOS=19.4-r3-s7
Juniper JUNOS=20.1
Juniper JUNOS=20.1-r1
Juniper JUNOS=20.1-r1-s1
Juniper JUNOS=20.1-r1-s2
Juniper JUNOS=20.1-r1-s3
Juniper JUNOS=20.1-r1-s4
Juniper JUNOS=20.1-r2
Juniper JUNOS=20.1-r2-s1
Juniper JUNOS=20.1-r2-s2
Juniper JUNOS=20.1-r3
Juniper JUNOS=20.1-r3-s1
Juniper JUNOS=20.1-r3-s2
Juniper JUNOS=20.1-r3-s3
Juniper JUNOS=20.2
Juniper JUNOS=20.2-r1
Juniper JUNOS=20.2-r1-s1
Juniper JUNOS=20.2-r1-s2
Juniper JUNOS=20.2-r1-s3
Juniper JUNOS=20.2-r2
Juniper JUNOS=20.2-r2-s1
Juniper JUNOS=20.2-r2-s2
Juniper JUNOS=20.2-r2-s3
Juniper JUNOS=20.2-r3
Juniper JUNOS=20.2-r3-s1
Juniper JUNOS=20.2-r3-s2
Juniper JUNOS=20.2-r3-s3
Juniper JUNOS=20.3
Juniper JUNOS=20.3-r1
Juniper JUNOS=20.3-r1-s1
Juniper JUNOS=20.3-r1-s2
Juniper JUNOS=20.3-r2
Juniper JUNOS=20.3-r2-s1
Juniper JUNOS=20.3-r3
Juniper JUNOS=20.3-r3-s1
Juniper JUNOS=20.4
Juniper JUNOS=20.4-r1
Juniper JUNOS=20.4-r1-s1
Juniper JUNOS=20.4-r2
Juniper JUNOS=20.4-r2-s1
Juniper JUNOS=20.4-r2-s2
Juniper JUNOS=20.4-r3
Juniper JUNOS=20.4-r3-s1
Juniper JUNOS=21.1
Juniper JUNOS=21.1-r1
Juniper JUNOS=21.1-r1-s1
Juniper JUNOS=21.1-r2
Juniper JUNOS=21.1-r2-s1
Juniper JUNOS=21.1-r2-s2
Juniper JUNOS=21.2
Juniper JUNOS=21.2-r1
Juniper JUNOS=21.2-r1-s1
Juniper JUNOS=21.2-r1-s2
Juniper JUNOS=21.2-r2
Juniper JUNOS=21.3-r1
Juniper JUNOS=21.3-r1-s1
Juniper JUNOS=21.3-r1-s2
Juniper QFX10002
Juniper QFX10008
Juniper QFX10016

Remediation

Information

The following software releases have been updated to resolve this specific issue: Junos OS 19.1R3-S9, 19.2R1-S9, 19.2R3-S5, 19.3R3-S6, 19.4R2-S7, 19.4R3-S8, 20.1R3-S4, 20.2R3-S4, 20.3R3-S2, 20.4R3-S2, 21.1R3, 21.2R2-S1, 21.2R3, 21.3R2, 21.4R1, and all subsequent releases.

Event History

Jul 20, 2022
CVE Published
via MITRE·02:15 PM
Data Sourced
via MITRE·02:15 PM
RemedyDescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-22217?

CVE-2022-22217 has a severity rating that indicates it could lead to a Denial of Service (DoS) due to improper checks in Juniper Networks Junos OS.

2

How do I fix CVE-2022-22217?

To fix CVE-2022-22217, users should upgrade their Junos OS to a version higher than 19.1 that is not affected by this vulnerability.

3

What type of vulnerability is CVE-2022-22217?

CVE-2022-22217 is classified as an Improper Check for Unusual or Exceptional Conditions vulnerability.

4

What devices are affected by CVE-2022-22217?

CVE-2022-22217 affects multiple versions of Juniper Networks Junos OS across numerous devices including Routers and Switches.

5

Can CVE-2022-22217 be exploited remotely?

Yes, CVE-2022-22217 can be exploited by an adjacent unauthenticated attacker which increases the risk of remote Denial of Service attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203