7.5

CVE-2022-22228

Junos OS: IPv6 OAM SRv6 network-enabled devices are vulnerable to Denial of Service (DoS) due to RPD memory leak upon receipt of specific a IPv6 packet

An Improper Validation of Specified Type of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an attacker to cause an RPD memory leak leading to a Denial of Service (DoS). This memory leak only occurs when the attacker's packets are destined to any configured IPv6 address on the device. This issue affects: Juniper Networks Junos OS 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R2; 22.1 versions prior to 22.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 21.1R1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Version 21.1 Update -
Juniper ≫ Junos Version 21.1 Update r1
Juniper ≫ Junos Version 21.1 Update r1-s1
Juniper ≫ Junos Version 21.1 Update r2
Juniper ≫ Junos Version 21.1 Update r2-s1
Juniper ≫ Junos Version 21.1 Update r2-s2
Juniper ≫ Junos Version 21.1 Update r3
Juniper ≫ Junos Version 21.1 Update r3-s1
Juniper ≫ Junos Version 21.2 Update -
Juniper ≫ Junos Version 21.2 Update r1
Juniper ≫ Junos Version 21.2 Update r1-s1
Juniper ≫ Junos Version 21.2 Update r1-s2
Juniper ≫ Junos Version 21.2 Update r2
Juniper ≫ Junos Version 21.2 Update r2-s1
Juniper ≫ Junos Version 21.2 Update r2-s2
Juniper ≫ Junos Version 21.2 Update r3
Juniper ≫ Junos Version 21.3 Update -
Juniper ≫ Junos Version 21.3 Update r1
Juniper ≫ Junos Version 21.3 Update r1-s1
Juniper ≫ Junos Version 21.3 Update r1-s2
Juniper ≫ Junos Version 21.3 Update r2
Juniper ≫ Junos Version 21.3 Update r2-s1
Juniper ≫ Junos Version 21.3 Update r2-s2
Juniper ≫ Junos Version 21.4 Update -
Juniper ≫ Junos Version 21.4 Update r1
Juniper ≫ Junos Version 21.4 Update r1-s1
Juniper ≫ Junos Version 21.4 Update r1-s2
Juniper ≫ Junos Version 22.1 Update r1
Juniper ≫ Junos Version 22.1 Update r1-s1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.66% 0.485
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Juniper 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-1287 Improper Validation of Specified Type of Input

The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.