CVE-2022-22236: Junos OS: SRX Series and MX Series: When specific valid SIP packets are received the PFE will crash
An Access of Uninitialized Pointer vulnerability in SIP Application Layer Gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When specific valid SIP packets are received the PFE will crash and restart. This issue affects Juniper Networks Junos OS on SRX Series and MX Series: 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S2; 21.3 versions prior to 21.3R2-S2, 21.3R3; 21.4 versions prior to 21.4R1-S2, 21.4R2; 22.1 versions prior to 22.1R1-S1, 22.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22236?
CVE-2022-22236 has been classified as a high-severity vulnerability due to its potential to cause Denial of Service.
How does CVE-2022-22236 affect Juniper Networks devices?
CVE-2022-22236 allows an unauthenticated, network-based attacker to exploit a vulnerability in the SIP Application Layer Gateway of Junos OS.
How do I fix CVE-2022-22236?
To fix CVE-2022-22236, you should upgrade your Junos OS to the latest secure version as provided by Juniper Networks.
Which versions of Junos OS are affected by CVE-2022-22236?
CVE-2022-22236 affects Junos OS versions 20.4 and 21.1 series, among others, as specified by the Juniper advisory.
Is CVE-2022-22236 a remote attack vector?
Yes, CVE-2022-22236 can be exploited remotely, allowing attackers to conduct Denial of Service attacks without authentication.