cbcvebase.
CVE-2022-22236
published 2022-10-18

CVE-2022-22236: An Access of Uninitialized Pointer vulnerability in SIP Application Layer Gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series allows an…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
An Access of Uninitialized Pointer vulnerability in SIP Application Layer Gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When specific valid SIP packets are received the PFE will crash and restart. This issue affects Juniper Networks Junos OS on SRX Series and MX Series: 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S2; 21.3 versions prior to 21.3R2-S2, 21.3R3; 21.4 versions prior to 21.4R1-S2, 21.4R2; 22.1 versions prior to 22.1R1-S1, 22.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.

Affected

15 ranges
VendorProductVersion rangeFixed in
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos_os
junipermx_series
junipersrx_series
juniper_networksjunos_os>= 20.4 < 20.4R3-S420.4R3-S4
juniper_networksjunos_os>= 21.1 < 21.1R3-S221.1R3-S2
juniper_networksjunos_os>= 21.2 < 21.2R3-S221.2R3-S2
juniper_networksjunos_os>= 21.3 < 21.3R2-S2, 21.3R321.3R2-S2, 21.3R3
juniper_networksjunos_os>= 21.4 < 21.4R1-S2, 21.4R221.4R1-S2, 21.4R2
juniper_networksjunos_os>= 22.1 < 22.1R1-S1, 22.1R222.1R1-S1, 22.1R2