Product Affected

This issue affects Junos OS Evolved 21.1-EVO, 21.2-EVO, 21.3-EVO, 21.4-EVO. Affected platforms: ACX7100-32C, ACX7100-48L, ACX7509.
Medium
5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Problem

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX7000 Series allows an unauthenticated network-based attacker to cause a partial Denial of Service (DoS).

On receipt of specific IPv6 transit traffic, Junos OS Evolved on ACX7100-48L, ACX7100-32C and ACX7509 sends this traffic to the Routing Engine (RE) instead of forwarding it, leading to increased CPU utilization of the RE and a partial DoS.

This issue only affects systems configured with IPv6.

This issue does not affect ACX7024 which is supported from 22.3R1-EVO onwards where the fix has already been incorporated as indicated in the solution section.

This issue affects Juniper Networks Junos OS Evolved on ACX7100-48L, ACX7100-32C, ACX7509:

  • 21.1-EVO versions prior to 21.1R3-S2-EVO;
  • 21.2-EVO versions prior to 21.2R3-S2-EVO;
  • 21.3-EVO versions prior to 21.3R3-EVO;
  • 21.4-EVO  versions prior to 21.4R1-S1-EVO, 21.4R2-EVO.

This issue does not affect Juniper Networks Junos OS Evolved versions prior to 21.1R1-EVO.

To be exposed to this vulnerability a device needs to be configured with a minimal IPv6 configuration like in the following example:

[interfaces <interface> unit <unit number> family inet6]

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue was seen during production usage.

This issue has been assigned CVE-2022-22227.

Solution

The following software releases have been updated to resolve this specific issue: 21.1R3-S2-EVO, 21.2R3-S2-EVO, 21.3R3-EVO, 21.4R1-S1-EVO, 21.4R2-EVO, 22.1R1-EVO, and all subsequent releases.

This issue is being tracked as PR 1641006 which is visible on the Customer Support website.

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

IMPLEMENTATION:

Software Releases, patches and updates are available at https://support.juniper.net/support/downloads/.

Workaround

There are no viable workarounds for this issue.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2022-10-12: Initial Publication.

Related Information