7.5

CVE-2022-22232

A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On SRX Series If Unified Threat Management (UTM) Enhanced Content Filtering (CF) is enabled and specific transit traffic is processed the PFE will crash and restart. This issue affects Juniper Networks Junos OS: 21.4 versions prior to 21.4R1-S2, 21.4R2 on SRX Series; 22.1 versions prior to 22.1R1-S1, 22.1R2 on SRX Series. This issue does not affect Juniper Networks Junos OS versions prior to 21.4R1.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JuniperJunos Version21.4 Update-
   JuniperSrx100 Version-
   JuniperSrx110 Version-
   JuniperSrx1400 Version-
   JuniperSrx1500 Version-
   JuniperSrx210 Version-
   JuniperSrx220 Version-
   JuniperSrx240 Version-
   JuniperSrx240h2 Version-
   JuniperSrx240m Version-
   JuniperSrx300 Version-
   JuniperSrx320 Version-
   JuniperSrx340 Version-
   JuniperSrx3400 Version-
   JuniperSrx345 Version-
   JuniperSrx3600 Version-
   JuniperSrx380 Version-
   JuniperSrx4000 Version-
   JuniperSrx4100 Version-
   JuniperSrx4200 Version-
   JuniperSrx4600 Version-
   JuniperSrx5000 Version-
   JuniperSrx5400 Version-
   JuniperSrx550 Version-
   JuniperSrx550 Hm Version-
   JuniperSrx550m Version-
   JuniperSrx5600 Version-
   JuniperSrx5800 Version-
   JuniperSrx650 Version-
JuniperJunos Version21.4 Updater1
   JuniperSrx100 Version-
   JuniperSrx110 Version-
   JuniperSrx1400 Version-
   JuniperSrx1500 Version-
   JuniperSrx210 Version-
   JuniperSrx220 Version-
   JuniperSrx240 Version-
   JuniperSrx240h2 Version-
   JuniperSrx240m Version-
   JuniperSrx300 Version-
   JuniperSrx320 Version-
   JuniperSrx340 Version-
   JuniperSrx3400 Version-
   JuniperSrx345 Version-
   JuniperSrx3600 Version-
   JuniperSrx380 Version-
   JuniperSrx4000 Version-
   JuniperSrx4100 Version-
   JuniperSrx4200 Version-
   JuniperSrx4600 Version-
   JuniperSrx5000 Version-
   JuniperSrx5400 Version-
   JuniperSrx550 Version-
   JuniperSrx550 Hm Version-
   JuniperSrx550m Version-
   JuniperSrx5600 Version-
   JuniperSrx5800 Version-
   JuniperSrx650 Version-
JuniperJunos Version21.4 Updater1-s1
   JuniperSrx100 Version-
   JuniperSrx110 Version-
   JuniperSrx1400 Version-
   JuniperSrx1500 Version-
   JuniperSrx210 Version-
   JuniperSrx220 Version-
   JuniperSrx240 Version-
   JuniperSrx240h2 Version-
   JuniperSrx240m Version-
   JuniperSrx300 Version-
   JuniperSrx320 Version-
   JuniperSrx340 Version-
   JuniperSrx3400 Version-
   JuniperSrx345 Version-
   JuniperSrx3600 Version-
   JuniperSrx380 Version-
   JuniperSrx4000 Version-
   JuniperSrx4100 Version-
   JuniperSrx4200 Version-
   JuniperSrx4600 Version-
   JuniperSrx5000 Version-
   JuniperSrx5400 Version-
   JuniperSrx550 Version-
   JuniperSrx550 Hm Version-
   JuniperSrx550m Version-
   JuniperSrx5600 Version-
   JuniperSrx5800 Version-
   JuniperSrx650 Version-
JuniperJunos Version22.1 Updater1
   JuniperSrx100 Version-
   JuniperSrx110 Version-
   JuniperSrx1400 Version-
   JuniperSrx1500 Version-
   JuniperSrx210 Version-
   JuniperSrx220 Version-
   JuniperSrx240 Version-
   JuniperSrx240h2 Version-
   JuniperSrx240m Version-
   JuniperSrx300 Version-
   JuniperSrx320 Version-
   JuniperSrx340 Version-
   JuniperSrx3400 Version-
   JuniperSrx345 Version-
   JuniperSrx3600 Version-
   JuniperSrx380 Version-
   JuniperSrx4000 Version-
   JuniperSrx4100 Version-
   JuniperSrx4200 Version-
   JuniperSrx4600 Version-
   JuniperSrx5000 Version-
   JuniperSrx5400 Version-
   JuniperSrx550 Version-
   JuniperSrx550 Hm Version-
   JuniperSrx550m Version-
   JuniperSrx5600 Version-
   JuniperSrx5800 Version-
   JuniperSrx650 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.584
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
sirt@juniper.net 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.