CVE-2022-22249: Junos OS: MX Series: An FPC crash might be seen due to mac-moves within the same bridge domain
An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When there is a continuous mac move a memory corruption causes one or more FPCs to crash and reboot. These MAC moves can be between two local interfaces or between core/EVPN and local interface. The below error logs can be seen in PFE syslog when this issue happens: xsseventhandler(1071): EA[0:0]PPE 46.xss[0] ADDR Error. ppeerrorinterrupt(4298): EA[0:0]PPE 46 Errors sync xtxn error xsseventhandler(1071): EA[0:0]PPE 1.xss[0] ADDR Error. ppeerrorinterrupt(4298): EA[0:0]PPE 1 Errors sync xtxn error xsseventhandler(1071): EA[0:0]PPE 2.xss[0] ADDR Error. This issue affects Juniper Networks Junos OS on MX Series: All versions prior to 15.1R7-S13; 19.1 versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S6; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 version 20.1R1 and later versions; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S2; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R3; 21.3 versions prior to 21.3R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22249?
CVE-2022-22249 is rated as a high-severity vulnerability due to its potential to cause a Denial of Service (DoS).
How do I fix CVE-2022-22249?
To mitigate CVE-2022-22249, you should upgrade your Junos OS to a fixed version as suggested in the vendor's advisory.
Which versions of Junos OS are affected by CVE-2022-22249?
CVE-2022-22249 affects Junos OS versions prior to 15.1 and between 15.1-r7 and 21.3.
Can CVE-2022-22249 be exploited remotely?
Yes, CVE-2022-22249 can be exploited by an unauthenticated adjacent attacker.
What are the potential impacts of CVE-2022-22249?
The exploitation of CVE-2022-22249 could lead to memory corruption, resulting in a Denial of Service (DoS) condition.