SB2022041362 - Improper initialization in Juniper Junos OS
Published: April 13, 2022
Security Bulletin ID
SB2022041362
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper initialization (CVE-ID: CVE-2022-22186)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on EX4650 devices, packets received on the management interface (em0) but not destined to the device, may be improperly forwarded to an egress interface, instead of being discarded.
Such traffic being sent by a client may appear genuine, but is non-standard in nature and should be considered as potentially malicious.
Remediation
Install update from vendor's website.