2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-22183" ,
"sourceIdentifier" : "sirt@juniper.net" ,
"published" : "2022-04-14T16:15:07.867" ,
2024-11-23 15:12:23 +00:00
"lastModified" : "2024-11-21T06:46:20.450" ,
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect to a specific open IPv4 port, which in affected releases should otherwise be unreachable, to cause the CPU to consume all resources as more traffic is sent to the port to create a Denial of Service (DoS) condition. Continued receipt and processing of these packets will create a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS Evolved 20.4 versions prior to 20.4R3-S2-EVO; 21.1 versions prior to 21.1R3-S1-EVO; 21.2 versions prior to 21.2R3-EVO; 21.3 versions prior to 21.3R2-EVO; 21.4 versions prior to 21.4R2-EVO. This issue does not affect Junos OS."
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad de Control de Acceso Inapropiado en Juniper Networks Junos OS Evolved permite que un atacante no autenticado basado en la red que sea capaz de conectarse a un puerto IPv4 abierto espec\u00edfico, que en las versiones afectadas deber\u00eda ser inalcanzable de otro modo, cause que la CPU consuma todos los recursos a medida que es enviado m\u00e1s tr\u00e1fico al puerto para crear una condici\u00f3n de Denegaci\u00f3n de Servicio (DoS). La recepci\u00f3n y el procesamiento continuos de estos paquetes crear\u00e1n una condici\u00f3n de Denegaci\u00f3n de Servicio (DoS) sostenida. Este problema afecta a: Juniper Networks Junos OS Evolved 20.4 versiones anteriores a 20.4R3-S2-EVO; 21.1 versiones anteriores a 21.1R3-S1-EVO; 21.2 versiones anteriores a 21.2R3-EVO; 21.3 versiones anteriores a 21.3R2-EVO; 21.4 versiones anteriores a 21.4R2-EVO. Este problema no afecta a Junos OS"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
2024-11-23 15:12:23 +00:00
"source" : "sirt@juniper.net" ,
"type" : "Secondary" ,
2023-04-24 12:24:31 +02:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
2024-11-23 15:12:23 +00:00
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-11-23 15:12:23 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 3.6
} ,
{
2024-11-23 15:12:23 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
2024-11-23 15:12:23 +00:00
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-11-23 15:12:23 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 3.6
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C" ,
2024-11-23 15:12:23 +00:00
"baseScore" : 7.8 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-11-23 15:12:23 +00:00
"availabilityImpact" : "COMPLETE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 10.0 ,
"impactScore" : 6.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
2023-06-27 20:00:33 +00:00
{
"source" : "sirt@juniper.net" ,
"type" : "Secondary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-16"
} ,
{
"lang" : "en" ,
"value" : "CWE-200"
} ,
{
"lang" : "en" ,
"value" : "CWE-284"
}
]
2024-11-23 15:12:23 +00:00
} ,
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
2023-04-24 12:24:31 +02:00
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:20.4:r1:*:*:*:*:*:*" ,
"matchCriteriaId" : "C9C8866D-162F-4C9B-8167-2FBA25410368"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:20.4:r1-s1:*:*:*:*:*:*" ,
"matchCriteriaId" : "F85E5BC7-8607-4330-AA72-2273D32F8604"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:20.4:r1-s2:*:*:*:*:*:*" ,
"matchCriteriaId" : "878C81C9-A418-4A21-8FDB-2116A992679C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:20.4:r2:*:*:*:*:*:*" ,
"matchCriteriaId" : "7451A671-A3CC-4904-8D45-947B1D3783C9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:20.4:r2-s1:*:*:*:*:*:*" ,
"matchCriteriaId" : "0108AD20-EAE6-41D1-AE48-254C46B5388A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:20.4:r2-s2:*:*:*:*:*:*" ,
"matchCriteriaId" : "44FBCA6F-EB05-4EE4-85FD-944BDAF7D81B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:20.4:r2-s3:*:*:*:*:*:*" ,
"matchCriteriaId" : "E554FD12-FE69-44D1-B2C9-4382F8CA4456"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:20.4:r3:*:*:*:*:*:*" ,
"matchCriteriaId" : "E0C1D53E-70BE-4246-89ED-1074C8C70747"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:20.4:r3-s1:*:*:*:*:*:*" ,
"matchCriteriaId" : "B39DDCF8-BB68-49F4-8AAF-AE25C9C13AC1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.1:r1:*:*:*:*:*:*" ,
"matchCriteriaId" : "AE674DD3-3590-4434-B144-5AD7EB5F039D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.1:r1-s1:*:*:*:*:*:*" ,
"matchCriteriaId" : "0099BDA9-9D4B-4D6C-8234-EFD9E8C63476"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.1:r2:*:*:*:*:*:*" ,
"matchCriteriaId" : "D8729BC1-FB09-4E6D-A5D5-8BDC589555B6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.1:r3:*:*:*:*:*:*" ,
"matchCriteriaId" : "9D72C3DF-4513-48AC-AAED-C1AADF0794E1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.2:r1:*:*:*:*:*:*" ,
"matchCriteriaId" : "3EA3DC63-B290-4D15-BEF9-21DEF36CA2EA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.2:r1-s1:*:*:*:*:*:*" ,
"matchCriteriaId" : "7E1E57AF-979B-4022-8AD6-B3558E06B718"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.2:r1-s2:*:*:*:*:*:*" ,
"matchCriteriaId" : "144730FB-7622-4B3D-9C47-D1B7A7FB7EB0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.2:r2:*:*:*:*:*:*" ,
"matchCriteriaId" : "7BA246F0-154E-4F44-A97B-690D22FA73DD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.2:r2-s1:*:*:*:*:*:*" ,
"matchCriteriaId" : "25D6C07C-F96E-4523-BB54-7FEABFE1D1ED"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.2:r2-s2:*:*:*:*:*:*" ,
"matchCriteriaId" : "2B70C784-534B-4FAA-A5ED-3709656E2B97"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.3:r1:*:*:*:*:*:*" ,
"matchCriteriaId" : "5A4DD04A-DE52-46BE-8C34-8DB47F7500F0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.3:r1-s1:*:*:*:*:*:*" ,
"matchCriteriaId" : "FEE0E145-8E1C-446E-90ED-237E3B9CAF47"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.4:r1:*:*:*:*:*:*" ,
"matchCriteriaId" : "8B73A41D-3FF5-4E53-83FF-74DF58E0D6C3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:juniper:junos_os_evolved:21.4:r1-s1:*:*:*:*:*:*" ,
"matchCriteriaId" : "CEDF46A8-FC3A-4779-B695-2CA11D045AEB"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://kb.juniper.net/JSA69516" ,
"source" : "sirt@juniper.net" ,
"tags" : [
"Vendor Advisory"
]
2024-11-23 15:12:23 +00:00
} ,
{
"url" : "https://kb.juniper.net/JSA69516" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}