CVE-2022-22175
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
An Improper Locking vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated networked attacker to cause a flowprocessing daemon (flowd) crash and thereby a Denial of Service (DoS). Continued receipt of these specific packets will cause a sustained Denial of Service condition. This issue can occur in a scenario where the SIP ALG is enabled and specific SIP messages are being processed simultaneously. This issue affects: Juniper Networks Junos OS on MX Series and SRX Series 20.4 versions prior to 20.4R3-S1; 21.1 versions prior to 21.1R2-S2, 21.1R3; 21.2 versions prior to 21.2R1-S2, 21.2R2; 21.3 versions prior to 21.3R1-S1, 21.3R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.
Affected (13)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 20.4 r1-s1 |
| Running on/with | Platform Versions |
|---|---|
Juniper Mx10 | All versions |
Juniper Mx10000 | All versions |
Juniper Mx10003 | All versions |
Juniper Mx10008 | All versions |
Juniper Mx10016 | All versions |
Juniper Mx104 | All versions |
Juniper Mx150 | All versions |
Juniper Mx2008 | All versions |
Juniper Mx2010 | All versions |
Juniper Mx2020 | All versions |
Juniper Mx204 | All versions |
Juniper Mx240 | All versions |
Juniper Mx40 | All versions |
Juniper Mx480 | All versions |
Juniper Mx5 | All versions |
Juniper Mx80 | All versions |
Juniper Mx960 | All versions |
Juniper Srx100 | All versions |
Juniper Srx110 | All versions |
Juniper Srx1400 | All versions |
Juniper Srx1500 | All versions |
Juniper Srx210 | All versions |
Juniper Srx220 | All versions |
Juniper Srx240 | All versions |
Juniper Srx240h2 | All versions |
Juniper Srx300 | All versions |
Juniper Srx320 | All versions |
Juniper Srx340 | All versions |
Juniper Srx3400 | All versions |
Juniper Srx345 | All versions |
Juniper Srx3600 | All versions |
Juniper Srx380 | All versions |
Juniper Srx4000 | All versions |
Juniper Srx4100 | All versions |
Juniper Srx4200 | All versions |
Juniper Srx4600 | All versions |
Juniper Srx5000 | All versions |
Juniper Srx5400 | All versions |
Juniper Srx550 | All versions |
Juniper Srx550 Hm | All versions |
Juniper Srx550m | All versions |
Juniper Srx5600 | All versions |
Juniper Srx5800 | All versions |
Juniper Srx650 | All versions |
References (2)
Timeline
No history available yet.