ue to the Improper Handling of an Unexpected Data Type in the processing of EVPN routes on Juniper Networks Junos OS and Junos OS Evolved, an attacker in direct control of a BGP client connected to a route reflector, or via a machine in the middle (MITM) attack, can send a specific EVPN route contained within a BGP Update, triggering a routing protocol daemon (RPD) crash, leading to a Denial of Service (DoS) condition. Continued receipt and processing of these specific EVPN routes could create a sustained Denial of Service (DoS) condition. This issue only occurs on BGP route reflectors, only within a BGP EVPN multicast environment, and only when one or more BGP clients have 'leave-sync-route-oldstyle' enabled. This issue affects: Juniper Networks Junos OS 21.3 versions prior to 21.3R3-S2; 21.4 versions prior to 21.4R2-S2, 21.4R3; 22.1 versions prior to 22.1R1-S2, 22.1R3; 22.2 versions prior to 22.2R2. Juniper Networks Junos OS Evolved 21.3 version 21.3R1-EVO and later versions prior to 21.4R3-EVO; 22.1 versions prior to 22.1R1-S2-EVO, 22.1R3-EVO; 22.2 versions prior to 22.2R2-EVO. This issue does not affect: Juniper Networks Junos OS versions prior to 21.3R1. Juniper Networks Junos OS Evolved versions prior to 21.3R1-EVO.
| Link | Resource |
|---|---|
| https://kb.juniper.net/JSA69898 | Mitigation Vendor Advisory |
| https://www.juniper.net/documentation/us/en/software/junos/evpn-vxlan/topics/ref/statement/evpn-edit-routing-instances-protocols.html | Vendor Advisory |
| https://kb.juniper.net/JSA69898 | Mitigation Vendor Advisory |
| https://www.juniper.net/documentation/us/en/software/junos/evpn-vxlan/topics/ref/statement/evpn-edit-routing-instances-protocols.html | Vendor Advisory |
Configuration 1 (hide)
|
Configuration 2 (hide)
|
21 Nov 2024, 06:46
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://kb.juniper.net/JSA69898 - Mitigation, Vendor Advisory | |
| References | () https://www.juniper.net/documentation/us/en/software/junos/evpn-vxlan/topics/ref/statement/evpn-edit-routing-instances-protocols.html - Vendor Advisory |
Published : 2022-10-18 03:15
Updated : 2024-11-21 06:46
NVD link : CVE-2022-22219
Mitre link : CVE-2022-22219
CVE.ORG link : CVE-2022-22219
JSON object : View