6.5
CVSSv3

CVE-2022-22210

Published: 20/07/2022 Updated: 29/07/2022
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX5000 Series and MX Series allows an unauthenticated adjacent malicious user to cause a Denial of Service (DoS). On QFX5K Series and MX Series, when the PFE receives a specific VxLAN packet the Layer 2 Address Learning Manager (L2ALM) process will crash leading to an FPC reboot. Continued receipt of this specific packet will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks Junos OS on QFX5000 Series, MX Series: 20.3 versions before 20.3R3-S3; 20.4 versions before 20.4R3-S2; 21.2 versions before 21.2R2-S1. This issue does not affect Juniper Networks Junos OS: All versions before 20.3R1; 21.1 version 21.1R1 and later versions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

juniper junos 20.3

juniper junos 20.4

juniper junos 21.2