CVE-2022-22218: Junos OS: SRX Series: Upon processing of a genuine packet the pkid process will crash during CMPv2 auto-re-enrollment
On SRX Series devices, an Improper Check for Unusual or Exceptional Conditions when using Certificate Management Protocol Version 2 (CMPv2) auto re-enrollment, allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS) by crashing the pkid process. The pkid process cannot handle an unexpected response from the Certificate Authority (CA) server, leading to crash. A restart is required to restore services. This issue affects: Juniper Networks Junos OS on SRX Series: All versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R3-S9; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S4; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S1; 21.2 versions prior to 21.2R3; 21.3 versions prior to 21.3R2; 21.4 versions prior to 21.4R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22218?
CVE-2022-22218 is classified as a high severity vulnerability due to its potential to cause a Denial of Service (DoS).
How do I fix CVE-2022-22218?
To remediate CVE-2022-22218, upgrade the affected Junos OS to a patched version as recommended by Juniper Networks.
Which systems are affected by CVE-2022-22218?
CVE-2022-22218 affects Juniper SRX Series devices running specific versions of the Junos OS.
What type of attack does CVE-2022-22218 enable?
CVE-2022-22218 allows an unauthenticated attacker to execute a network-based attack that can crash the pkid process.
What impact does CVE-2022-22218 have on my network?
The impact of CVE-2022-22218 can lead to network disruptions as it may cause the affected device to become non-operational.