SB2022041362 - Improper initialization in Juniper Junos OS 



SB2022041362 - Improper initialization in Juniper Junos OS

Published: April 13, 2022

Security Bulletin ID SB2022041362
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper initialization (CVE-ID: CVE-2022-22186)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on EX4650 devices, packets received on the management interface (em0) but not destined to the device, may be improperly forwarded to an egress interface, instead of being discarded.

Such traffic being sent by a client may appear genuine, but is non-standard in nature and should be considered as potentially malicious.


Remediation

Install update from vendor's website.