CVE-2022-22188
An Uncontrolled Memory Allocation vulnerability leading to a Heap-based Buffer Overflow in the packet forwarding engine (PFE) of Juniper Networks Junos OS allows a network-based unauthenticated attacker to flood the device with traffic leading to a Denial of Service (DoS). The device must be configured with storm control profiling limiting the number of unknown broadcast, multicast, or unicast traffic to be vulnerable to this issue. This issue affects: Juniper Networks Junos OS on QFX5100/QFX5110/QFX5120/QFX5200/QFX5210/EX4600/EX4650 Series; 20.2 version 20.2R1 and later versions prior to 20.2R2. This issue does not affect: Juniper Networks Junos OS versions prior to 20.2R1.
Published:Apr 14, 2022
Last Modified:Nov 21, 2024
EPS:Apr 14, 2022
EPSS Score:0.01775
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Juniper
Product
Ex4600
Juniper
Ex4600
Vendor
Juniper
Product
Ex4650
Juniper
Ex4650
Vendor
Juniper
Product
Junos
Juniper
Junos
Vendor
Juniper
Product
Qfx5100
Juniper
Qfx5100
Vendor
Juniper
Product
Qfx5110
Juniper
Qfx5110
Vendor
Juniper
Product
Qfx5120
Juniper
Qfx5120
Vendor
Juniper
Product
Qfx5200
Juniper
Qfx5200
Vendor
Juniper
Product
Qfx5210
Juniper
Qfx5210
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
