
12/10/2022

3/8/2024
CVE-2022-22218: Junos OS: SRX Series: Upon processing of a genuine packet the pkid process will crash during CMPv2 auto-re-enrollment
First published: Wed Oct 12 2022(Updated: )
On SRX Series devices, an Improper Check for Unusual or Exceptional Conditions when using Certificate Management Protocol Version 2 (CMPv2) auto re-enrollment, allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS) by crashing the pkid process. The pkid process cannot handle an unexpected response from the Certificate Authority (CA) server, leading to crash. A restart is required to restore services. This issue affects: Juniper Networks Junos OS on SRX Series: All versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R3-S9; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S4; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S1; 21.2 versions prior to 21.2R3; 21.3 versions prior to 21.3R2; 21.4 versions prior to 21.4R2.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|
Junos OS Evolved | <19.1 | |
Junos OS Evolved | =19.1 | |
Junos OS Evolved | =19.1-r1 | |
Junos OS Evolved | =19.1-r1-s1 | |
Junos OS Evolved | =19.1-r1-s2 | |
Junos OS Evolved | =19.1-r1-s3 | |
Junos OS Evolved | =19.1-r1-s4 | |
Junos OS Evolved | =19.1-r1-s5 | |
Junos OS Evolved | =19.1-r1-s6 | |
Junos OS Evolved | =19.1-r2 | |
Junos OS Evolved | =19.1-r2-s1 | |
Junos OS Evolved | =19.1-r2-s2 | |
Junos OS Evolved | =19.1-r2-s3 | |
Junos OS Evolved | =19.1-r3 | |
Junos OS Evolved | =19.1-r3-s1 | |
Junos OS Evolved | =19.1-r3-s2 | |
Junos OS Evolved | =19.1-r3-s3 | |
Junos OS Evolved | =19.1-r3-s4 | |
Junos OS Evolved | =19.1-r3-s5 | |
Junos OS Evolved | =19.1-r3-s6 | |
Junos OS Evolved | =19.1-r3-s7 | |
Junos OS Evolved | =19.1-r3-s8 | |
Junos OS Evolved | =19.2 | |
Junos OS Evolved | =19.2-r1 | |
Junos OS Evolved | =19.2-r1-s1 | |
Junos OS Evolved | =19.2-r1-s2 | |
Junos OS Evolved | =19.2-r1-s3 | |
Junos OS Evolved | =19.2-r1-s4 | |
Junos OS Evolved | =19.2-r1-s5 | |
Junos OS Evolved | =19.2-r1-s6 | |
Junos OS Evolved | =19.2-r1-s7 | |
Junos OS Evolved | =19.2-r1-s8 | |
Junos OS Evolved | =19.2-r1-s9 | |
Junos OS Evolved | =19.2-r2 | |
Junos OS Evolved | =19.2-r2-s1 | |
Junos OS Evolved | =19.2-r3 | |
Junos OS Evolved | =19.2-r3-s1 | |
Junos OS Evolved | =19.2-r3-s2 | |
Junos OS Evolved | =19.2-r3-s3 | |
Junos OS Evolved | =19.2-r3-s4 | |
Junos OS Evolved | =19.2-r3-s5 | |
Junos OS Evolved | =19.3 | |
Junos OS Evolved | =19.3-r1 | |
Junos OS Evolved | =19.3-r1-s1 | |
Junos OS Evolved | =19.3-r2 | |
Junos OS Evolved | =19.3-r2-s1 | |
Junos OS Evolved | =19.3-r2-s2 | |
Junos OS Evolved | =19.3-r2-s3 | |
Junos OS Evolved | =19.3-r2-s4 | |
Junos OS Evolved | =19.3-r2-s5 | |
Junos OS Evolved | =19.3-r2-s6 | |
Junos OS Evolved | =19.3-r3 | |
Junos OS Evolved | =19.3-r3-s1 | |
Junos OS Evolved | =19.3-r3-s2 | |
Junos OS Evolved | =19.3-r3-s3 | |
Junos OS Evolved | =19.3-r3-s4 | |
Junos OS Evolved | =19.3-r3-s5 | |
Junos OS Evolved | =19.3-r3-s6 | |
Junos OS Evolved | =19.4 | |
Junos OS Evolved | =19.4-r1 | |
Junos OS Evolved | =19.4-r1-s1 | |
Junos OS Evolved | =19.4-r1-s2 | |
Junos OS Evolved | =19.4-r1-s3 | |
Junos OS Evolved | =19.4-r1-s4 | |
Junos OS Evolved | =19.4-r2 | |
Junos OS Evolved | =19.4-r2-s1 | |
Junos OS Evolved | =19.4-r2-s2 | |
Junos OS Evolved | =19.4-r2-s3 | |
Junos OS Evolved | =19.4-r2-s4 | |
Junos OS Evolved | =19.4-r2-s5 | |
Junos OS Evolved | =19.4-r2-s6 | |
Junos OS Evolved | =19.4-r3 | |
Junos OS Evolved | =19.4-r3-s1 | |
Junos OS Evolved | =19.4-r3-s2 | |
Junos OS Evolved | =19.4-r3-s3 | |
Junos OS Evolved | =19.4-r3-s4 | |
Junos OS Evolved | =19.4-r3-s5 | |
Junos OS Evolved | =19.4-r3-s6 | |
Junos OS Evolved | =19.4-r3-s7 | |
Junos OS Evolved | =19.4-r3-s8 | |
Junos OS Evolved | =20.2 | |
Junos OS Evolved | =20.2-r1 | |
Junos OS Evolved | =20.2-r1-s1 | |
Junos OS Evolved | =20.2-r1-s2 | |
Junos OS Evolved | =20.2-r1-s3 | |
Junos OS Evolved | =20.2-r2 | |
Junos OS Evolved | =20.2-r2-s1 | |
Junos OS Evolved | =20.2-r2-s2 | |
Junos OS Evolved | =20.2-r2-s3 | |
Junos OS Evolved | =20.2-r3 | |
Junos OS Evolved | =20.2-r3-s1 | |
Junos OS Evolved | =20.2-r3-s2 | |
Junos OS Evolved | =20.2-r3-s3 | |
Junos OS Evolved | =20.2-r3-s4 | |
Junos OS Evolved | =20.3 | |
Junos OS Evolved | =20.3-r1 | |
Junos OS Evolved | =20.3-r1-s1 | |
Junos OS Evolved | =20.3-r1-s2 | |
Junos OS Evolved | =20.3-r2 | |
Junos OS Evolved | =20.3-r2-s1 | |
Junos OS Evolved | =20.3-r3 | |
Junos OS Evolved | =20.3-r3-s1 | |
Junos OS Evolved | =20.3-r3-s2 | |
Junos OS Evolved | =20.3-r3-s3 | |
Junos OS Evolved | =20.4 | |
Junos OS Evolved | =20.4-r1 | |
Junos OS Evolved | =20.4-r1-s1 | |
Junos OS Evolved | =20.4-r2 | |
Junos OS Evolved | =20.4-r2-s1 | |
Junos OS Evolved | =20.4-r2-s2 | |
Junos OS Evolved | =20.4-r3 | |
Junos OS Evolved | =20.4-r3-s1 | |
Junos OS Evolved | =20.4-r3-s2 | |
Junos OS Evolved | =20.4-r3-s3 | |
Junos OS Evolved | =21.1 | |
Junos OS Evolved | =21.1-r1 | |
Junos OS Evolved | =21.1-r1-s1 | |
Junos OS Evolved | =21.1-r2 | |
Junos OS Evolved | =21.1-r2-s1 | |
Junos OS Evolved | =21.1-r2-s2 | |
Junos OS Evolved | =21.1-r3 | |
Junos OS Evolved | =21.2 | |
Junos OS Evolved | =21.2-r1 | |
Junos OS Evolved | =21.2-r1-s1 | |
Junos OS Evolved | =21.2-r1-s2 | |
Junos OS Evolved | =21.2-r2 | |
Junos OS Evolved | =21.2-r2-s1 | |
Junos OS Evolved | =21.2-r2-s2 | |
Junos OS Evolved | =21.3 | |
Junos OS Evolved | =21.3-r1 | |
Junos OS Evolved | =21.3-r1-s1 | |
Junos OS Evolved | =21.3-r1-s2 | |
Junos OS Evolved | =21.4 | |
Junos OS Evolved | =21.4-r1 | |
Junos OS Evolved | =21.4-r1-s1 | |
Junos OS Evolved | =21.4-r1-s2 | |
Juniper SRX100 | | |
Juniper SRX110 | | |
Juniper SRX1400 | | |
Juniper SRX1500 | | |
Juniper SRX210 | | |
Juniper SRX220 | | |
Juniper SRX240 | | |
Juniper SRX240H2 | | |
Juniper SRX240M | | |
Juniper SRX300 | | |
Juniper SRX320 | | |
Juniper SRX340 | | |
Juniper SRX3400 | | |
Juniper SRX345 | | |
Juniper SRX3600 | | |
Juniper SRX380 | | |
Juniper SRX4000 | | |
Juniper SRX4100 | | |
Juniper SRX4200 | | |
Juniper SRX4600 | | |
Junos OS SRX 5000 Series | | |
Juniper SRX5400 | | |
Juniper SRX550 | | |
Juniper SRX550 | | |
Juniper SRX550 | | |
Juniper SRX5600 | | |
Juniper SRX5800 | | |
Juniper SRX650 | | |
Remedy
The following software releases have been updated to resolve this specific issue:
Junos OS: 19.1R3-S9, 19.2R3-S6, 19.3R3-S7, 19.4R2-S7, 19.4R3-S9, 20.2R3-S5, 20.3R3-S4, 20.4R3-S4, 21.1R3-S1, 21.2R3, 21.3R2, 21.4R1-S2, 21.4R2, 22.1R1, and all subsequent releases.
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is the severity of CVE-2022-22218?
CVE-2022-22218 is classified as a high severity vulnerability due to its potential to cause a Denial of Service (DoS).
How do I fix CVE-2022-22218?
To remediate CVE-2022-22218, upgrade the affected Junos OS to a patched version as recommended by Juniper Networks.
Which systems are affected by CVE-2022-22218?
CVE-2022-22218 affects Juniper SRX Series devices running specific versions of the Junos OS.
What type of attack does CVE-2022-22218 enable?
CVE-2022-22218 allows an unauthenticated attacker to execute a network-based attack that can crash the pkid process.
What impact does CVE-2022-22218 have on my network?
The impact of CVE-2022-22218 can lead to network disruptions as it may cause the affected device to become non-operational.
- agent/type
- collector/mitre-cve
- source/MITRE
- agent/remedy
- agent/severity
- agent/author
- agent/weakness
- agent/title
- agent/last-modified-date
- agent/references
- agent/description
- agent/first-publish-date
- agent/event
- agent/source
- agent/tags
- agent/softwarecombine
- collector/nvd-index
- agent/software-canonical-lookup-request
- vendor/juniper
- canonical/junos os evolved
- version/junos os evolved/19.1
- version/junos os evolved/19.1-r1
- version/junos os evolved/19.1-r1-s1
- version/junos os evolved/19.1-r1-s2
- version/junos os evolved/19.1-r1-s3
- version/junos os evolved/19.1-r1-s4
- version/junos os evolved/19.1-r1-s5
- version/junos os evolved/19.1-r1-s6
- version/junos os evolved/19.1-r2
- version/junos os evolved/19.1-r2-s1
- version/junos os evolved/19.1-r2-s2
- version/junos os evolved/19.1-r2-s3
- version/junos os evolved/19.1-r3
- version/junos os evolved/19.1-r3-s1
- version/junos os evolved/19.1-r3-s2
- version/junos os evolved/19.1-r3-s3
- version/junos os evolved/19.1-r3-s4
- version/junos os evolved/19.1-r3-s5
- version/junos os evolved/19.1-r3-s6
- version/junos os evolved/19.1-r3-s7
- version/junos os evolved/19.1-r3-s8
- version/junos os evolved/19.2
- version/junos os evolved/19.2-r1
- version/junos os evolved/19.2-r1-s1
- version/junos os evolved/19.2-r1-s2
- version/junos os evolved/19.2-r1-s3
- version/junos os evolved/19.2-r1-s4
- version/junos os evolved/19.2-r1-s5
- version/junos os evolved/19.2-r1-s6
- version/junos os evolved/19.2-r1-s7
- version/junos os evolved/19.2-r1-s8
- version/junos os evolved/19.2-r1-s9
- version/junos os evolved/19.2-r2
- version/junos os evolved/19.2-r2-s1
- version/junos os evolved/19.2-r3
- version/junos os evolved/19.2-r3-s1
- version/junos os evolved/19.2-r3-s2
- version/junos os evolved/19.2-r3-s3
- version/junos os evolved/19.2-r3-s4
- version/junos os evolved/19.2-r3-s5
- version/junos os evolved/19.3
- version/junos os evolved/19.3-r1
- version/junos os evolved/19.3-r1-s1
- version/junos os evolved/19.3-r2
- version/junos os evolved/19.3-r2-s1
- version/junos os evolved/19.3-r2-s2
- version/junos os evolved/19.3-r2-s3
- version/junos os evolved/19.3-r2-s4
- version/junos os evolved/19.3-r2-s5
- version/junos os evolved/19.3-r2-s6
- version/junos os evolved/19.3-r3
- version/junos os evolved/19.3-r3-s1
- version/junos os evolved/19.3-r3-s2
- version/junos os evolved/19.3-r3-s3
- version/junos os evolved/19.3-r3-s4
- version/junos os evolved/19.3-r3-s5
- version/junos os evolved/19.3-r3-s6
- version/junos os evolved/19.4
- version/junos os evolved/19.4-r1
- version/junos os evolved/19.4-r1-s1
- version/junos os evolved/19.4-r1-s2
- version/junos os evolved/19.4-r1-s3
- version/junos os evolved/19.4-r1-s4
- version/junos os evolved/19.4-r2
- version/junos os evolved/19.4-r2-s1
- version/junos os evolved/19.4-r2-s2
- version/junos os evolved/19.4-r2-s3
- version/junos os evolved/19.4-r2-s4
- version/junos os evolved/19.4-r2-s5
- version/junos os evolved/19.4-r2-s6
- version/junos os evolved/19.4-r3
- version/junos os evolved/19.4-r3-s1
- version/junos os evolved/19.4-r3-s2
- version/junos os evolved/19.4-r3-s3
- version/junos os evolved/19.4-r3-s4
- version/junos os evolved/19.4-r3-s5
- version/junos os evolved/19.4-r3-s6
- version/junos os evolved/19.4-r3-s7
- version/junos os evolved/19.4-r3-s8
- version/junos os evolved/20.2
- version/junos os evolved/20.2-r1
- version/junos os evolved/20.2-r1-s1
- version/junos os evolved/20.2-r1-s2
- version/junos os evolved/20.2-r1-s3
- version/junos os evolved/20.2-r2
- version/junos os evolved/20.2-r2-s1
- version/junos os evolved/20.2-r2-s2
- version/junos os evolved/20.2-r2-s3
- version/junos os evolved/20.2-r3
- version/junos os evolved/20.2-r3-s1
- version/junos os evolved/20.2-r3-s2
- version/junos os evolved/20.2-r3-s3
- version/junos os evolved/20.2-r3-s4
- version/junos os evolved/20.3
- version/junos os evolved/20.3-r1
- version/junos os evolved/20.3-r1-s1
- version/junos os evolved/20.3-r1-s2
- version/junos os evolved/20.3-r2
- version/junos os evolved/20.3-r2-s1
- version/junos os evolved/20.3-r3
- version/junos os evolved/20.3-r3-s1
- version/junos os evolved/20.3-r3-s2
- version/junos os evolved/20.3-r3-s3
- version/junos os evolved/20.4
- version/junos os evolved/20.4-r1
- version/junos os evolved/20.4-r1-s1
- version/junos os evolved/20.4-r2
- version/junos os evolved/20.4-r2-s1
- version/junos os evolved/20.4-r2-s2
- version/junos os evolved/20.4-r3
- version/junos os evolved/20.4-r3-s1
- version/junos os evolved/20.4-r3-s2
- version/junos os evolved/20.4-r3-s3
- version/junos os evolved/21.1
- version/junos os evolved/21.1-r1
- version/junos os evolved/21.1-r1-s1
- version/junos os evolved/21.1-r2
- version/junos os evolved/21.1-r2-s1
- version/junos os evolved/21.1-r2-s2
- version/junos os evolved/21.1-r3
- version/junos os evolved/21.2
- version/junos os evolved/21.2-r1
- version/junos os evolved/21.2-r1-s1
- version/junos os evolved/21.2-r1-s2
- version/junos os evolved/21.2-r2
- version/junos os evolved/21.2-r2-s1
- version/junos os evolved/21.2-r2-s2
- version/junos os evolved/21.3
- version/junos os evolved/21.3-r1
- version/junos os evolved/21.3-r1-s1
- version/junos os evolved/21.3-r1-s2
- version/junos os evolved/21.4
- version/junos os evolved/21.4-r1
- version/junos os evolved/21.4-r1-s1
- version/junos os evolved/21.4-r1-s2
- canonical/juniper srx100
- canonical/juniper srx110
- canonical/juniper srx1400
- canonical/juniper srx1500
- canonical/juniper srx210
- canonical/juniper srx220
- canonical/juniper srx240
- canonical/juniper srx240h2
- canonical/juniper srx240m
- canonical/juniper srx300
- canonical/juniper srx320
- canonical/juniper srx340
- canonical/juniper srx3400
- canonical/juniper srx345
- canonical/juniper srx3600
- canonical/juniper srx380
- canonical/juniper srx4000
- canonical/juniper srx4100
- canonical/juniper srx4200
- canonical/juniper srx4600
- canonical/junos os srx 5000 series
- canonical/juniper srx5400
- canonical/juniper srx550
- canonical/juniper srx5600
- canonical/juniper srx5800
- canonical/juniper srx650
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203