← back
CVE-2022-22201

SRX5000 Series with SPC3, SRX4000 Series, and vSRX: When PowerMode IPsec is configured, the PFE will crash upon receipt of a malformed ESP packet

CVSS 7.5 HIGHEPSS 0.6%CWE-1285
In short

A firewall device (Juniper SRX) can crash when it receives a malformed encrypted network packet if a specific security feature (PowerMode IPsec) is enabled. An attacker on the network can trigger this crash without needing special access, causing the firewall to stop working temporarily.

Technical detail

The Packet Forwarding Engine (PFE) in Juniper SRX devices fails to properly validate the structure of ESP (Encapsulating Security Payload) packets when PowerMode IPsec is active, allowing an unauthenticated network-based attacker to craft malformed packets matching an established IPsec tunnel and trigger a PFE crash, resulting in Denial of Service. Affected platforms include SRX5000 Series with SPC3, SRX4000 Series, and vSRX across multiple Junos OS versions prior to specified patches.

Summary generated and translated by AI from the official description.
An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). On SRX5000 Series with SPC3, SRX4000 Series, and vSRX, when PowerMode IPsec is configured and a malformed ESP packet matching an established IPsec tunnel is received the PFE crashes. This issue affects Juniper Networks Junos OS on SRX5000 Series with SPC3, SRX4000 Series, and vSRX: All versions prior to 19.4R2-S6, 19.4R3-S7; 20.1 versions prior to 20.1R3-S3; 20.2 versions prior to 20.2R3-S4; 20.3 versions prior to 20.3R3-S3; 20.4 versions prior to 20.4R3-S2; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R3; 21.3 versions prior to 21.3R1-S2, 21.3R2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →