« Volver al listado

CVE-2022-22183

Estado: ModificadaAlta (7.5)—

An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect to a specific open IPv4 port, which in affected releases should otherwise be unreachable, to cause the CPU to consume all resources as more traffic is sent to the port to create a Denial of Service (DoS) condition. Continued receipt and processing of these packets will create a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS Evolved 20.4 versions prior to 20.4R3-S2-EVO; 21.1 versions prior to 21.1R3-S1-EVO; 21.2 versions prior to 21.2R3-EVO; 21.3 versions prior to 21.3R2-EVO; 21.4 versions prior to 21.4R2-EVO. This issue does not affect Junos OS.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-22183",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "sirt@juniper.net",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "sirt@juniper.net",
      "affectedData": [
        {
          "vendor": "Juniper Networks",
          "product": "Junos OS Evolved",
          "versions": [
            {
              "status": "affected",
              "version": "20.4",
              "lessThan": "20.4R3-S2-EVO",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "21.1",
              "lessThan": "21.1R3-S1-EVO",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "21.2",
              "lessThan": "21.2R3-EVO",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "21.3",
              "lessThan": "21.3R2-EVO",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "21.4",
              "lessThan": "21.4R2-EVO",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Juniper Networks",
          "product": "Junos OS",
          "versions": [
            {
              "status": "unaffected",
              "version": "Any"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-04-14T16:15:07.867",
  "references": [
    {
      "url": "https://kb.juniper.net/JSA69516",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "sirt@juniper.net"
    },
    {
      "url": "https://kb.juniper.net/JSA69516",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "sirt@juniper.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-16"
        },
        {
          "lang": "en",
          "value": "CWE-200"
        },
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect to a specific open IPv4 port, which in affected releases should otherwise be unreachable, to cause the CPU to consume all resources as more traffic is sent to the port to create a Denial of Service (DoS) condition. Continued receipt and processing of these packets will create a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS Evolved 20.4 versions prior to 20.4R3-S2-EVO; 21.1 versions prior to 21.1R3-S1-EVO; 21.2 versions prior to 21.2R3-EVO; 21.3 versions prior to 21.3R2-EVO; 21.4 versions prior to 21.4R2-EVO. This issue does not affect Junos OS."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de Control de Acceso Inapropiado en Juniper Networks Junos OS Evolved permite que un atacante no autenticado basado en la red que sea capaz de conectarse a un puerto IPv4 abierto específico, que en las versiones afectadas debería ser inalcanzable de otro modo, cause que la CPU consuma todos los recursos a medida que es enviado más tráfico al puerto para crear una condición de Denegación de Servicio (DoS). La recepción y el procesamiento continuos de estos paquetes crearán una condición de Denegación de Servicio (DoS) sostenida. Este problema afecta a: Juniper Networks Junos OS Evolved 20.4 versiones anteriores a 20.4R3-S2-EVO; 21.1 versiones anteriores a 21.1R3-S1-EVO; 21.2 versiones anteriores a 21.2R3-EVO; 21.3 versiones anteriores a 21.3R2-EVO; 21.4 versiones anteriores a 21.4R2-EVO. Este problema no afecta a Junos OS"
    }
  ],
  "lastModified": "2026-06-17T04:27:56.937",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:20.4:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9C8866D-162F-4C9B-8167-2FBA25410368"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:20.4:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F85E5BC7-8607-4330-AA72-2273D32F8604"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:20.4:r1-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "878C81C9-A418-4A21-8FDB-2116A992679C"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:20.4:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7451A671-A3CC-4904-8D45-947B1D3783C9"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:20.4:r2-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0108AD20-EAE6-41D1-AE48-254C46B5388A"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:20.4:r2-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44FBCA6F-EB05-4EE4-85FD-944BDAF7D81B"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:20.4:r2-s3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E554FD12-FE69-44D1-B2C9-4382F8CA4456"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:20.4:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0C1D53E-70BE-4246-89ED-1074C8C70747"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:20.4:r3-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B39DDCF8-BB68-49F4-8AAF-AE25C9C13AC1"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.1:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE674DD3-3590-4434-B144-5AD7EB5F039D"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.1:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0099BDA9-9D4B-4D6C-8234-EFD9E8C63476"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.1:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D8729BC1-FB09-4E6D-A5D5-8BDC589555B6"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.1:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D72C3DF-4513-48AC-AAED-C1AADF0794E1"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.2:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EA3DC63-B290-4D15-BEF9-21DEF36CA2EA"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.2:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E1E57AF-979B-4022-8AD6-B3558E06B718"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.2:r1-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "144730FB-7622-4B3D-9C47-D1B7A7FB7EB0"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.2:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BA246F0-154E-4F44-A97B-690D22FA73DD"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.2:r2-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25D6C07C-F96E-4523-BB54-7FEABFE1D1ED"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.2:r2-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B70C784-534B-4FAA-A5ED-3709656E2B97"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.3:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A4DD04A-DE52-46BE-8C34-8DB47F7500F0"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.3:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FEE0E145-8E1C-446E-90ED-237E3B9CAF47"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.4:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B73A41D-3FF5-4E53-83FF-74DF58E0D6C3"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:21.4:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CEDF46A8-FC3A-4779-B695-2CA11D045AEB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "sirt@juniper.net"
}