4.3
CVSSv2

CVE-2022-22175

Published: 19/01/2022 Updated: 26/01/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An Improper Locking vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated networked malicious user to cause a flowprocessing daemon (flowd) crash and thereby a Denial of Service (DoS). Continued receipt of these specific packets will cause a sustained Denial of Service condition. This issue can occur in a scenario where the SIP ALG is enabled and specific SIP messages are being processed simultaneously. This issue affects: Juniper Networks Junos OS on MX Series and SRX Series 20.4 versions before 20.4R3-S1; 21.1 versions before 21.1R2-S2, 21.1R3; 21.2 versions before 21.2R1-S2, 21.2R2; 21.3 versions before 21.3R1-S1, 21.3R2. This issue does not affect Juniper Networks Junos OS versions before 20.4R1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

juniper junos 20.4

juniper junos 21.1

juniper junos 21.2

juniper junos 21.3