Skip to main content
HIGH

CVE-2022-22188

CVSS v3

7.5

HIGH

EPSS Score

1.8 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An Uncontrolled Memory Allocation vulnerability leading to a Heap-based Buffer Overflow in the packet forwarding engine (PFE) of Juniper Networks Junos OS allows a network-based unauthenticated attacker to flood the device with traffic leading to a Denial of Service (DoS). The device must be configured with storm control profiling limiting the number of unknown broadcast, multicast, or unicast traffic to be vulnerable to this issue. This issue affects: Juniper Networks Junos OS on QFX5100/QFX5110/QFX5120/QFX5200/QFX5210/EX4600/EX4650 Series; 20.2 version 20.2R1 and later versions prior to 20.2R2. This issue does not affect: Juniper Networks Junos OS versions prior to 20.2R1.

Technical details

Published
2022-04-14

Frequently asked questions

What is CVE-2022-22188?

An Uncontrolled Memory Allocation vulnerability leading to a Heap-based Buffer Overflow in the packet forwarding engine (PFE) of Juniper Networks Junos OS allows a network-based unauthenticated attacker to flood the device with traffic leading to a Denial of Service (DoS). The device must be configured with storm control profiling limiting the number of unknown broadcast, multicast, or unicast traffic to be vulnerable to this issue. This issue affects: Juniper Networks Junos OS on QFX5100/QFX5110/QFX5120/QFX5200/QFX5210/EX4600/EX4650 Series; 20.2 version 20.2R1 and later versions prior to 20.2R2. This issue does not affect: Juniper Networks Junos OS versions prior to 20.2R1.

Is CVE-2022-22188 actively exploited?

Active exploitation of CVE-2022-22188 has not been confirmed. The EPSS score is 1.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-22188?

CVE-2022-22188 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2022-22188 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key