CVE-2022-22217: Junos OS: QFX10K Series: Denial of Service (DoS) upon receipt of crafted MLD packets on multi-homing ESI in VXLAN
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). The issue is caused by malformed MLD packets looping on a multi-homed Ethernet Segment Identifier (ESI) when VXLAN is configured. These MLD packets received on a multi-homed ESI are sent to the peer, and then incorrectly forwarded out the same ESI, violating the split horizon rule. This issue only affects QFX10K Series switches, including the QFX10002, QFX10008, and QFX10016. Other products and platforms are unaffected by this vulnerability. This issue affects Juniper Networks Junos OS on QFX10K Series: All versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R1-S9, 19.2R3-S5; 19.3 versions prior to 19.3R3-S6; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 versions prior to 20.1R3-S4; 20.2 versions prior to 20.2R3-S4; 20.3 versions prior to 20.3R3-S2; 20.4 versions prior to 20.4R3-S2; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R2-S1, 21.2R3; 21.3 versions prior to 21.3R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22217?
CVE-2022-22217 has a severity rating that indicates it could lead to a Denial of Service (DoS) due to improper checks in Juniper Networks Junos OS.
How do I fix CVE-2022-22217?
To fix CVE-2022-22217, users should upgrade their Junos OS to a version higher than 19.1 that is not affected by this vulnerability.
What type of vulnerability is CVE-2022-22217?
CVE-2022-22217 is classified as an Improper Check for Unusual or Exceptional Conditions vulnerability.
What devices are affected by CVE-2022-22217?
CVE-2022-22217 affects multiple versions of Juniper Networks Junos OS across numerous devices including Routers and Switches.
Can CVE-2022-22217 be exploited remotely?
Yes, CVE-2022-22217 can be exploited by an adjacent unauthenticated attacker which increases the risk of remote Denial of Service attacks.