2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-22198" ,
"sourceIdentifier" : "sirt@juniper.net" ,
"published" : "2022-04-14T16:15:08.653" ,
2024-11-23 15:12:23 +00:00
"lastModified" : "2024-11-21T06:46:22.510" ,
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "An Access of Uninitialized Pointer vulnerability in the SIP ALG of Juniper Networks Junos OS allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Continued receipt of these specific packets will cause a sustained Denial of Service condition. On all MX and SRX platforms, if the SIP ALG is enabled, an MS-MPC or MS-MIC, or SPC will crash if it receives a SIP message with a specific contact header format. This issue affects Juniper Networks Junos OS on MX Series and SRX Series: 20.4 versions prior to 20.4R3; 21.1 versions prior to 21.1R2-S1, 21.1R3; 21.2 versions prior to 21.2R2. This issue does not affect versions prior to 20.4R1."
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad de Acceso de Puntero no Inicializado en la SIP ALG de Juniper Networks Junos OS permite a un atacante no autenticado basado en la red causar una Denegaci\u00f3n de Servicio (DoS). La recepci\u00f3n continuada de estos paquetes espec\u00edficos causar\u00e1 una condici\u00f3n de denegaci\u00f3n de servicio sostenida. En todas las plataformas MX y SRX, si la ALG de SIP est\u00e1 habilitada, un MS-MPC o MS-MIC, o SPC ser\u00e1 bloqueado si recibe un mensaje SIP con un formato de encabezado de contacto espec\u00edfico. Este problema afecta a Juniper Networks Junos OS en las series MX y SRX: versiones 20.4 anteriores a 20.4R3; versiones 21.1 anteriores a 21.1R2-S1, 21.1R3; versiones 21.2 anteriores a 21.2R2. Este problema no afecta a versiones anteriores a 20.4R1"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
2024-11-23 15:12:23 +00:00
"source" : "sirt@juniper.net" ,
"type" : "Secondary" ,
2023-04-24 12:24:31 +02:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
2024-11-23 15:12:23 +00:00
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-11-23 15:12:23 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 3.6
} ,
{
2024-11-23 15:12:23 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
2024-11-23 15:12:23 +00:00
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-11-23 15:12:23 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 3.6
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C" ,
2024-11-23 15:12:23 +00:00
"baseScore" : 7.1 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-11-23 15:12:23 +00:00
"availabilityImpact" : "COMPLETE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 6.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
2024-11-23 15:12:23 +00:00
"source" : "sirt@juniper.net" ,
"type" : "Secondary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-824"
}
]
} ,
{
2024-11-23 15:12:23 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-824"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos:20.4:r1:*:*:*:*:*:*" ,
"matchCriteriaId" : "20DDC6B7-BFC4-4F0B-8E68-442C23765BF2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos:20.4:r1-s1:*:*:*:*:*:*" ,
"matchCriteriaId" : "037BA01C-3F5C-4503-A633-71765E9EF774"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos:20.4:r2:*:*:*:*:*:*" ,
"matchCriteriaId" : "C54B047C-4B38-40C0-9855-067DCF7E48BD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos:20.4:r2-s1:*:*:*:*:*:*" ,
"matchCriteriaId" : "38984199-E332-4A9C-A4C0-78083D052E15"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos:20.4:r2-s2:*:*:*:*:*:*" ,
"matchCriteriaId" : "AA6526FB-2941-4D18-9B2E-472AD5A62A53"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos:21.1:r1:*:*:*:*:*:*" ,
"matchCriteriaId" : "625BA7E6-D2AD-4A48-9B94-24328BE5B06A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos:21.1:r1-s1:*:*:*:*:*:*" ,
"matchCriteriaId" : "F462F4E3-762C-429F-8D25-5521100DD37C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos:21.1:r2:*:*:*:*:*:*" ,
"matchCriteriaId" : "C0BC9DAC-D6B5-4C5E-8C73-6E550D9A30F5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos:21.2:r1:*:*:*:*:*:*" ,
"matchCriteriaId" : "A52AF794-B36B-43A6-82E9-628658624B0A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos:21.2:r1-s1:*:*:*:*:*:*" ,
"matchCriteriaId" : "3998DC76-F72F-4452-9150-652140B113EB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos:21.2:r1-s2:*:*:*:*:*:*" ,
"matchCriteriaId" : "36ED4552-2420-45F9-B6E4-6DA2B2B12870"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx10:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "52699E2B-450A-431C-81E3-DC4483C8B4F2"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx10000:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D97AF6F8-3D50-4D35-BCB1-54E3BEC69B9F"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx10003:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D5627740-42E3-4FB1-B8B9-0B768AFFA1EC"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx10008:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D6F0EA2F-BF7E-45D0-B2B4-8A7B67A9475A"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx10016:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C39DA74D-F5C7-4C11-857D-50631A110644"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx104:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F72C850A-0530-4DB7-A553-7E19F82122B5"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx150:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7FE2089C-F341-4DC1-B76D-633BC699306D"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx2008:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2FEF33EB-B2E0-42EF-A1BB-D41021B6D08F"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx2010:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "27175D9A-CA2C-4218-8042-835E25DFCA43"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx2020:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "00C7FC57-8ACF-45AA-A227-7E3B350FD24F"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx204:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2754C2DF-DF6E-4109-9463-38B4E0465B77"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx240:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F4A26704-A6A4-4C4F-9E12-A0A0259491EF"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx40:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C982A2FF-A1F9-4830-BAB6-77CFCE1F093F"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx480:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "104858BD-D31D-40E0-8524-2EC311F10EAC"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx5:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3B557965-0040-4048-B56C-F564FF28635B"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx80:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EB875EBD-A3CD-4466-B2A3-39D47FF94592"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:mx960:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B5E08E1E-0FE4-4294-9497-BBFFECA2A220"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx100:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "561C1113-3D59-4DD9-ADA7-3C9ECC4632EC"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx110:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "78C6D8A0-92D3-4FD3-BCC1-CC7C87B76317"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx1400:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "927EAB8B-EC3B-4B12-85B9-5517EBA49A30"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx1500:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2CEBF85C-736A-4E7D-956A-3E8210D4F70B"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx210:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CD647C15-A686-4C8F-A766-BC29404C0FED"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx220:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "45AB1622-1AED-4CD7-98F1-67779CDFC321"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx240:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "89276D88-3B8D-4168-A2CD-0920297485F2"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx240h2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E020556B-693F-4963-BA43-3164AB50FA49"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx300:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BB5AB24B-2B43-43DD-AE10-F758B4B19F2A"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx320:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "80F9DC32-5ADF-4430-B1A6-357D0B29DB78"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx340:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8B82D4C4-7A65-409A-926F-33C054DCBFBA"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx3400:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "746C3882-2A5B-4215-B259-EB1FD60C513D"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx345:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CE535749-F4CE-4FFA-B23D-BF09C92481E5"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx3600:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DDE64EC0-7E42-43AF-A8FA-1A233BD3E3BC"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx380:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2305DA9D-E6BA-48F4-80CF-9E2DE7661B2F"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx4000:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "06A03463-6B1D-4DBA-9E89-CAD5E899B98B"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx4100:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3AA8999C-8AE4-416F-BA2A-B1A21F33B4D7"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx4200:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CCC5F6F5-4347-49D3-909A-27A3A96D36C9"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx4600:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "56BA6B86-D3F4-4496-AE46-AC513C6560FA"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx5000:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5ABA347C-3EF3-4F75-B4D1-54590A57C2BC"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx5400:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2FDDC897-747F-44DD-9599-7266F9B5B7B1"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx550:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "62FC145A-D477-4C86-89E7-F70F52773801"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx550_hm:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "06685D0E-A075-49A5-9EF4-34F0F795C8C6"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx550m:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "52F0B735-8C49-4B08-950A-296C9CDE43CA"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx5600:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "68CA098D-CBE4-4E62-9EC0-43E1B6098710"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx5800:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "66F474D4-79B6-4525-983C-9A9011BD958B"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:juniper:srx650:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8AA424D4-4DBF-4E8C-96B8-E37741B5403E"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://kb.juniper.net/JSA69513" ,
"source" : "sirt@juniper.net" ,
"tags" : [
"Mitigation" ,
"Vendor Advisory"
]
2024-11-23 15:12:23 +00:00
} ,
{
"url" : "https://kb.juniper.net/JSA69513" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mitigation" ,
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}