CVE-2022-22236

HIGH

Juniper Junos - Denial of Service

Title source: rule
STIX 2.1

Description

An Access of Uninitialized Pointer vulnerability in SIP Application Layer Gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When specific valid SIP packets are received the PFE will crash and restart. This issue affects Juniper Networks Junos OS on SRX Series and MX Series: 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S2; 21.3 versions prior to 21.3R2-S2, 21.3R3; 21.4 versions prior to 21.4R1-S2, 21.4R2; 22.1 versions prior to 22.1R1-S1, 22.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.

Scores

CVSS v3 7.5
EPSS 0.0045
EPSS Percentile 63.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-824
Status published
Products (6)
juniper/junos 20.4 (10 CPE variants)
juniper/junos 21.1 (8 CPE variants)
juniper/junos 21.2 (9 CPE variants)
juniper/junos 21.3 (9 CPE variants)
juniper/junos 21.4 (3 CPE variants)
juniper/junos 22.1 r1
Published Oct 18, 2022
Tracked Since Feb 18, 2026