Product Affected

This issue affects all versions of Junos OS. Affected platforms: MX Series with SPC3, SRX Series.
High
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Problem

An Insufficient Algorithmic Complexity combined with an Allocation of Resources Without Limits or Throttling vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated network attacker to cause latency in transit packet processing and even packet loss.

If transit traffic includes a significant percentage (> 5%) of fragmented packets which need to be reassembled, high latency or packet drops might be observed.

This issue affects Juniper Networks Junos OS on SPC3 used in SRX5000 series and MX series, SRX4000 series, and vSRX :

  • All versions prior to 18.2R3;
  • 18.3 versions prior to 18.3R3;
  • 18.4 versions prior to 18.4R2-S9, 18.4R3;
  • 19.1 versions prior to 19.1R2;
  • 19.2 versions prior to 19.2R1-S1, 19.2R2.

This is issue does not affect SRX300 series, SRX550, SRX1500 and cSRX.

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue was seen during production usage.

This issue has been assigned  CVE-2022-22153 .

Solution

The following software releases have been updated to resolve this specific issue: 18.2R3, 18.3R3, 18.4R2-S9, 18.4R3, 19.1R2, 19.2R1-S1, 19.2R2, 19.3R1, and all subsequent releases.

This issue is being tracked as  1406465 .

Software releases or updates are available for download at https://support.juniper.net/support/downloads/

Workaround

There are no viable workarounds for this issue.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2022-01-12: Initial Publication.
2022-02-18: Affected platforms updated.

Related Information