7.5
CVSSv3

CVE-2022-22201

Published: 18/10/2022 Updated: 20/10/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated network-based malicious user to cause a Denial of Service (DoS). On SRX5000 Series with SPC3, SRX4000 Series, and vSRX, when PowerMode IPsec is configured and a malformed ESP packet matching an established IPsec tunnel is received the PFE crashes. This issue affects Juniper Networks Junos OS on SRX5000 Series with SPC3, SRX4000 Series, and vSRX: All versions before 19.4R2-S6, 19.4R3-S7; 20.1 versions before 20.1R3-S3; 20.2 versions before 20.2R3-S4; 20.3 versions before 20.3R3-S3; 20.4 versions before 20.4R3-S2; 21.1 versions before 21.1R3; 21.2 versions before 21.2R3; 21.3 versions before 21.3R1-S2, 21.3R2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

juniper junos 19.4

juniper junos 20.1

juniper junos 20.2

juniper junos 20.3

juniper junos 20.4

juniper junos 21.3

juniper junos 21.1

juniper junos 21.2

juniper junos