CVE-2022-22238: Junos OS and Junos OS Evolved: The rpd process will crash when a malformed incoming RESV message is processed
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When an incoming RESV message corresponding to a protected LSP is malformed it causes an incorrect internal state resulting in an rpd core. This issue affects: Juniper Networks Junos OS All versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S6; 19.4 versions prior to 19.4R3-S8; 20.1 versions prior to 20.1R3-S2; 20.2 versions prior to 20.2R3-S3; 20.3 versions prior to 20.3R3-S2; 20.4 versions prior to 20.4R3-S1; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R1-S2, 21.2R3; 21.3 versions prior to 21.3R2. Juniper Networks Junos OS Evolved All versions prior to 20.2R3-S3-EVO; 20.3-EVO version 20.3R1-EVO and later versions; 20.4-EVO versions prior to 20.4R3-S1-EVO; 21.1-EVO version 21.1R1-EVO and later versions; 21.2-EVO version 21.2R1-EVO and later versions; 21.3-EVO versions prior to 21.3R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22238?
CVE-2022-22238 has been rated as a high severity vulnerability due to its potential to cause a Denial of Service (DoS).
How do I fix CVE-2022-22238?
To fix CVE-2022-22238, you should upgrade your Junos OS to a version higher than 19.4 or apply the recommended security patches from Juniper Networks.
Who is affected by CVE-2022-22238?
CVE-2022-22238 affects Juniper Networks' Junos OS and Junos OS Evolved in several versions up to 19.4.
What types of attacks can exploit CVE-2022-22238?
CVE-2022-22238 can be exploited by unauthenticated adjacent attackers to send malformed RESV messages, leading to a Denial of Service.
When was CVE-2022-22238 reported?
CVE-2022-22238 was officially reported in early 2022, and Juniper Networks has since addressed the issue with updates.