CVE Feed

    Dashboard / CVE / CVE-2022-22211

    CVE-2022-22211

    A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved on PTX Series allows an unprivileged attacker to cause Denial of Service (DoS). Continuously polling the SNMP jnxCosQstatTable causes the FPC to run out of GUID space, causing a Denial of Service to the FPC resources. When the FPC runs out of the GUID space, you will see the following syslog messages. The evo-aftmand-bt process is asserting. fpc1 evo-aftmand-bt[17556]: %USER-3: get_next_guid: Ran out of Guid Space start 1748051689472 end 1752346656767 fpc1 audit[17556]: %AUTH-5: ANOM_ABEND auid=4294967295 uid=0 gid=0 ses=4294967295 pid=17556 comm="EvoAftManBt-mai" exe="/usr/sbin/evo-aftmand-bt" sig=6 fpc1 kernel: %KERN-5: audit: type=1701 audit(1648567505.119:57): auid=4294967295 uid=0 gid=0 ses=4294967295 pid=17556 comm="EvoAftManBt-mai" exe="/usr/sbin/evo-aftmand-bt" sig=6 fpc1 emfd-fpa[14438]: %USER-5: Alarm set: APP color=red, class=CHASSIS, reason=Application evo-aftmand-bt fail on node Fpc1 fpc1 emfd-fpa[14438]: %USER-3-EMF_FPA_ALARM_REP: RaiseAlarm: Alarm(Location: /Chassis[0]/Fpc[1] Module: sysman Object: evo-aftmand-bt:0 Error: 2) reported fpc1 sysepochman[12738]: %USER-5-SYSTEM_REBOOT_EVENT: Reboot [node] [ungraceful reboot] [evo-aftmand-bt exited] The FPC resources can be monitored using the following commands: user@router> start shell [vrf:none] user@router-re0:~$ cli -c "show platform application-info allocations app evo-aftmand-bt" | grep ^fpc | grep -v Route | grep -i -v Nexthop | awk '{total[$1] += $5} END { for (key in total) { print key " " total[key]/4294967296 }}' Once the FPCs become unreachable they must be manually restarted as they do not self-recover. This issue affects Juniper Networks Junos OS Evolved on PTX Series: All versions prior to 20.4R3-S4-EVO; 21.1-EVO version 21.1R1-EVO and later versions; 21.2-EVO version 21.2R1-EVO and later versions; 21.3-EVO versions prior to 21.3R3-EVO; 21.4-EVO versions prior to 21.4R2-EVO; 22.1-EVO versions prior to 22.1R2-EVO.

    Published:Oct 18, 2022
    Last Modified:May 12, 2025
    EPS:Oct 18, 2022
    EPSS Score:0.00092
    CVSS Score:7.5

    Affected Products

    Vendor
    Juniper
    Product
    Junos Os Evolved
    Vendor
    Juniper
    Product
    Ptx1000
    Vendor
    Juniper
    Product
    Ptx1000-72q
    Vendor
    Juniper
    Product
    Ptx10000
    Vendor
    Juniper
    Product
    Ptx10001
    Vendor
    Juniper
    Product
    Ptx10001-36mr
    Vendor
    Juniper
    Product
    Ptx100016
    Vendor
    Juniper
    Product
    Ptx10002
    Vendor
    Juniper
    Product
    Ptx10002-60c
    Vendor
    Juniper
    Product
    Ptx10003
    Vendor
    Juniper
    Product
    Ptx10003 160c
    Vendor
    Juniper
    Product
    Ptx10003 80c
    Vendor
    Juniper
    Product
    Ptx10003 81cd
    Vendor
    Juniper
    Product
    Ptx10004
    Vendor
    Juniper
    Product
    Ptx10008
    Vendor
    Juniper
    Product
    Ptx10016
    Vendor
    Juniper
    Product
    Ptx3000
    Vendor
    Juniper
    Product
    Ptx5000

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High