5.9

CVE-2022-22219

Junos OS and Junos OS Evolved: RPD core upon receipt of a specific EVPN route by a BGP route reflector in an EVPN environment

Due to the Improper Handling of an Unexpected Data Type in the processing of EVPN routes on Juniper Networks Junos OS and Junos OS Evolved, an attacker in direct control of a BGP client connected to a route reflector, or via a machine in the middle (MITM) attack, can send a specific EVPN route contained within a BGP Update, triggering a routing protocol daemon (RPD) crash, leading to a Denial of Service (DoS) condition. Continued receipt and processing of these specific EVPN routes could create a sustained Denial of Service (DoS) condition. This issue only occurs on BGP route reflectors, only within a BGP EVPN multicast environment, and only when one or more BGP clients have 'leave-sync-route-oldstyle' enabled. This issue affects: Juniper Networks Junos OS 21.3 versions prior to 21.3R3-S2; 21.4 versions prior to 21.4R2-S2, 21.4R3; 22.1 versions prior to 22.1R1-S2, 22.1R3; 22.2 versions prior to 22.2R2. Juniper Networks Junos OS Evolved 21.3 version 21.3R1-EVO and later versions prior to 21.4R3-EVO; 22.1 versions prior to 22.1R1-S2-EVO, 22.1R3-EVO; 22.2 versions prior to 22.2R2-EVO. This issue does not affect: Juniper Networks Junos OS versions prior to 21.3R1. Juniper Networks Junos OS Evolved versions prior to 21.3R1-EVO.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Version 21.3 Update -
Juniper ≫ Junos Version 21.3 Update r1
Juniper ≫ Junos Version 21.3 Update r1-s1
Juniper ≫ Junos Version 21.3 Update r1-s2
Juniper ≫ Junos Version 21.3 Update r2
Juniper ≫ Junos Version 21.3 Update r2-s1
Juniper ≫ Junos Version 21.3 Update r2-s2
Juniper ≫ Junos Version 21.3 Update r3
Juniper ≫ Junos Version 21.3 Update r3-s1
Juniper ≫ Junos Version 21.4 Update -
Juniper ≫ Junos Version 21.4 Update r1
Juniper ≫ Junos Version 21.4 Update r1-s1
Juniper ≫ Junos Version 21.4 Update r1-s2
Juniper ≫ Junos Version 21.4 Update r2
Juniper ≫ Junos Version 21.4 Update r2-s1
Juniper ≫ Junos Version 22.1 Update r1
Juniper ≫ Junos Version 22.1 Update r1-s1
Juniper ≫ Junos Version 22.1 Update r2
Juniper ≫ Junos Version 22.1 Update r2-s2
Juniper ≫ Junos Version 22.2 Update r1
Juniper ≫ Junos Version 22.2 Update r1-s1
Juniper ≫ Junos Os Evolved Version 21.3 Update r1
Juniper ≫ Junos Os Evolved Version 21.3 Update r1-s1
Juniper ≫ Junos Os Evolved Version 21.3 Update r2
Juniper ≫ Junos Os Evolved Version 21.3 Update r2-s1
Juniper ≫ Junos Os Evolved Version 21.3 Update r2-s2
Juniper ≫ Junos Os Evolved Version 22.1 Update r1
Juniper ≫ Junos Os Evolved Version 22.1 Update r1-s1
Juniper ≫ Junos Os Evolved Version 22.2 Update r1
Juniper ≫ Junos Os Evolved Version 22.2 Update r1-s1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.46
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Juniper 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-241 Improper Handling of Unexpected Data Type

The product does not handle or incorrectly handles when a particular element is not the expected type, e.g. it expects a digit (0-9) but is provided with a letter (A-Z).

https://kb.juniper.net/JSA69898
Vendor Advisory
Mitigation
https://www.juniper.net/documentation/us/en/software/junos/evpn-vxlan/topics/ref/statement/evpn-edit-routing-instances-protocols.html
Vendor Advisory