Juniper Networks Security Update 25 November 2022

Juniper Networks has released a security update to address a high-severity vulnerability affecting Junos OS 22.3R1 and Junos OS Evolved 22.3R1-EVO.

The addressed vulnerability is caused by improper input validation in the Routing Protocol Daemon (rpd). The remote attacker could exploit this vulnerability by sending a specially-crafted BGP update message to cause a denial of service attack on the affected system.

Juniper Networks Junos OS and Junos OS Evolved denial of service (CVE-2022- 22184):

• CVSS: 7.5

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: None

• User Interaction: None

• Consequences: Denial of Service

Vulnerabilities
  • CVE-2022-22184
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Juniper Support Portal

References