CVE-2022-22236

HIGH

Juniper Junos OS 20.4-22.1 - Unauthenticated Denial of Service via SIP ALG Uninitialized Pointer

Title source: llm
STIX 2.1

Description

An Access of Uninitialized Pointer vulnerability in SIP Application Layer Gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When specific valid SIP packets are received the PFE will crash and restart. This issue affects Juniper Networks Junos OS on SRX Series and MX Series: 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S2; 21.3 versions prior to 21.3R2-S2, 21.3R3; 21.4 versions prior to 21.4R1-S2, 21.4R2; 22.1 versions prior to 22.1R1-S1, 22.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0062
EPSS Percentile 44.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-824
Status published
Products (6)
juniper/junos 20.4 (10 CPE variants)
juniper/junos 21.1 (8 CPE variants)
juniper/junos 21.2 (9 CPE variants)
juniper/junos 21.3 (9 CPE variants)
juniper/junos 21.4 (3 CPE variants)
juniper/junos 22.1 r1
Published Oct 18, 2022
Tracked Since Feb 18, 2026