First published: Wed Oct 12 2022(Updated: )
On SRX Series devices, an Improper Check for Unusual or Exceptional Conditions when using Certificate Management Protocol Version 2 (CMPv2) auto re-enrollment, allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS) by crashing the pkid process. The pkid process cannot handle an unexpected response from the Certificate Authority (CA) server, leading to crash. A restart is required to restore services. This issue affects: Juniper Networks Junos OS on SRX Series: All versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R3-S9; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S4; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S1; 21.2 versions prior to 21.2R3; 21.3 versions prior to 21.3R2; 21.4 versions prior to 21.4R2.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|---|---|
Juniper Junos | <19.1 | |
Juniper Junos | =19.1 | |
Juniper Junos | =19.1-r1 | |
Juniper Junos | =19.1-r1-s1 | |
Juniper Junos | =19.1-r1-s2 | |
Juniper Junos | =19.1-r1-s3 | |
Juniper Junos | =19.1-r1-s4 | |
Juniper Junos | =19.1-r1-s5 | |
Juniper Junos | =19.1-r1-s6 | |
Juniper Junos | =19.1-r2 | |
Juniper Junos | =19.1-r2-s1 | |
Juniper Junos | =19.1-r2-s2 | |
Juniper Junos | =19.1-r2-s3 | |
Juniper Junos | =19.1-r3 | |
Juniper Junos | =19.1-r3-s1 | |
Juniper Junos | =19.1-r3-s2 | |
Juniper Junos | =19.1-r3-s3 | |
Juniper Junos | =19.1-r3-s4 | |
Juniper Junos | =19.1-r3-s5 | |
Juniper Junos | =19.1-r3-s6 | |
Juniper Junos | =19.1-r3-s7 | |
Juniper Junos | =19.1-r3-s8 | |
Juniper Junos | =19.2 | |
Juniper Junos | =19.2-r1 | |
Juniper Junos | =19.2-r1-s1 | |
Juniper Junos | =19.2-r1-s2 | |
Juniper Junos | =19.2-r1-s3 | |
Juniper Junos | =19.2-r1-s4 | |
Juniper Junos | =19.2-r1-s5 | |
Juniper Junos | =19.2-r1-s6 | |
Juniper Junos | =19.2-r1-s7 | |
Juniper Junos | =19.2-r1-s8 | |
Juniper Junos | =19.2-r1-s9 | |
Juniper Junos | =19.2-r2 | |
Juniper Junos | =19.2-r2-s1 | |
Juniper Junos | =19.2-r3 | |
Juniper Junos | =19.2-r3-s1 | |
Juniper Junos | =19.2-r3-s2 | |
Juniper Junos | =19.2-r3-s3 | |
Juniper Junos | =19.2-r3-s4 | |
Juniper Junos | =19.2-r3-s5 | |
Juniper Junos | =19.3 | |
Juniper Junos | =19.3-r1 | |
Juniper Junos | =19.3-r1-s1 | |
Juniper Junos | =19.3-r2 | |
Juniper Junos | =19.3-r2-s1 | |
Juniper Junos | =19.3-r2-s2 | |
Juniper Junos | =19.3-r2-s3 | |
Juniper Junos | =19.3-r2-s4 | |
Juniper Junos | =19.3-r2-s5 | |
Juniper Junos | =19.3-r2-s6 | |
Juniper Junos | =19.3-r3 | |
Juniper Junos | =19.3-r3-s1 | |
Juniper Junos | =19.3-r3-s2 | |
Juniper Junos | =19.3-r3-s3 | |
Juniper Junos | =19.3-r3-s4 | |
Juniper Junos | =19.3-r3-s5 | |
Juniper Junos | =19.3-r3-s6 | |
Juniper Junos | =19.4 | |
Juniper Junos | =19.4-r1 | |
Juniper Junos | =19.4-r1-s1 | |
Juniper Junos | =19.4-r1-s2 | |
Juniper Junos | =19.4-r1-s3 | |
Juniper Junos | =19.4-r1-s4 | |
Juniper Junos | =19.4-r2 | |
Juniper Junos | =19.4-r2-s1 | |
Juniper Junos | =19.4-r2-s2 | |
Juniper Junos | =19.4-r2-s3 | |
Juniper Junos | =19.4-r2-s4 | |
Juniper Junos | =19.4-r2-s5 | |
Juniper Junos | =19.4-r2-s6 | |
Juniper Junos | =19.4-r3 | |
Juniper Junos | =19.4-r3-s1 | |
Juniper Junos | =19.4-r3-s2 | |
Juniper Junos | =19.4-r3-s3 | |
Juniper Junos | =19.4-r3-s4 | |
Juniper Junos | =19.4-r3-s5 | |
Juniper Junos | =19.4-r3-s6 | |
Juniper Junos | =19.4-r3-s7 | |
Juniper Junos | =19.4-r3-s8 | |
Juniper Junos | =20.2 | |
Juniper Junos | =20.2-r1 | |
Juniper Junos | =20.2-r1-s1 | |
Juniper Junos | =20.2-r1-s2 | |
Juniper Junos | =20.2-r1-s3 | |
Juniper Junos | =20.2-r2 | |
Juniper Junos | =20.2-r2-s1 | |
Juniper Junos | =20.2-r2-s2 | |
Juniper Junos | =20.2-r2-s3 | |
Juniper Junos | =20.2-r3 | |
Juniper Junos | =20.2-r3-s1 | |
Juniper Junos | =20.2-r3-s2 | |
Juniper Junos | =20.2-r3-s3 | |
Juniper Junos | =20.2-r3-s4 | |
Juniper Junos | =20.3 | |
Juniper Junos | =20.3-r1 | |
Juniper Junos | =20.3-r1-s1 | |
Juniper Junos | =20.3-r1-s2 | |
Juniper Junos | =20.3-r2 | |
Juniper Junos | =20.3-r2-s1 | |
Juniper Junos | =20.3-r3 | |
Juniper Junos | =20.3-r3-s1 | |
Juniper Junos | =20.3-r3-s2 | |
Juniper Junos | =20.3-r3-s3 | |
Juniper Junos | =20.4 | |
Juniper Junos | =20.4-r1 | |
Juniper Junos | =20.4-r1-s1 | |
Juniper Junos | =20.4-r2 | |
Juniper Junos | =20.4-r2-s1 | |
Juniper Junos | =20.4-r2-s2 | |
Juniper Junos | =20.4-r3 | |
Juniper Junos | =20.4-r3-s1 | |
Juniper Junos | =20.4-r3-s2 | |
Juniper Junos | =20.4-r3-s3 | |
Juniper Junos | =21.1 | |
Juniper Junos | =21.1-r1 | |
Juniper Junos | =21.1-r1-s1 | |
Juniper Junos | =21.1-r2 | |
Juniper Junos | =21.1-r2-s1 | |
Juniper Junos | =21.1-r2-s2 | |
Juniper Junos | =21.1-r3 | |
Juniper Junos | =21.2 | |
Juniper Junos | =21.2-r1 | |
Juniper Junos | =21.2-r1-s1 | |
Juniper Junos | =21.2-r1-s2 | |
Juniper Junos | =21.2-r2 | |
Juniper Junos | =21.2-r2-s1 | |
Juniper Junos | =21.2-r2-s2 | |
Juniper Junos | =21.3 | |
Juniper Junos | =21.3-r1 | |
Juniper Junos | =21.3-r1-s1 | |
Juniper Junos | =21.3-r1-s2 | |
Juniper Junos | =21.4 | |
Juniper Junos | =21.4-r1 | |
Juniper Junos | =21.4-r1-s1 | |
Juniper Junos | =21.4-r1-s2 | |
Juniper SRX100 | ||
Juniper SRX110 | ||
Juniper SRX1400 | ||
Juniper SRX1500 | ||
Juniper SRX210 | ||
Juniper SRX220 | ||
Juniper SRX240 | ||
Juniper SRX240H2 | ||
Juniper SRX240M | ||
Juniper SRX300 | ||
Juniper SRX320 | ||
Juniper SRX340 | ||
Juniper SRX3400 | ||
Juniper SRX345 | ||
Juniper SRX3600 | ||
Juniper SRX380 | ||
Juniper SRX4000 | ||
Juniper SRX4100 | ||
Juniper SRX4200 | ||
Juniper SRX4600 | ||
Junos OS SRX 5000 Series | ||
Juniper SRX5400 | ||
Juniper SRX550 | ||
Juniper SRX550 | ||
Juniper SRX550 | ||
juniper srx5600 | ||
Juniper SRX5800 | ||
Juniper SRX650 |
The following software releases have been updated to resolve this specific issue: Junos OS: 19.1R3-S9, 19.2R3-S6, 19.3R3-S7, 19.4R2-S7, 19.4R3-S9, 20.2R3-S5, 20.3R3-S4, 20.4R3-S4, 21.1R3-S1, 21.2R3, 21.3R2, 21.4R1-S2, 21.4R2, 22.1R1, and all subsequent releases.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22218 is classified as a high severity vulnerability due to its potential to cause a Denial of Service (DoS).
To remediate CVE-2022-22218, upgrade the affected Junos OS to a patched version as recommended by Juniper Networks.
CVE-2022-22218 affects Juniper SRX Series devices running specific versions of the Junos OS.
CVE-2022-22218 allows an unauthenticated attacker to execute a network-based attack that can crash the pkid process.
The impact of CVE-2022-22218 can lead to network disruptions as it may cause the affected device to become non-operational.