VYPR
Unrated severityNVD Advisory· Published Oct 18, 2022· Updated May 12, 2025

Junos OS: SRX Series: Upon processing of a genuine packet the pkid process will crash during CMPv2 auto-re-enrollment

CVE-2022-22218

Description

On SRX Series devices, an Improper Check for Unusual or Exceptional Conditions when using Certificate Management Protocol Version 2 (CMPv2) auto re-enrollment, allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS) by crashing the pkid process. The pkid process cannot handle an unexpected response from the Certificate Authority (CA) server, leading to crash. A restart is required to restore services. This issue affects: Juniper Networks Junos OS on SRX Series: All versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R3-S9; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S4; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S1; 21.2 versions prior to 21.2R3; 21.3 versions prior to 21.3R2; 21.4 versions prior to 21.4R2.

Affected products

2
  • Juniper Networks/Junosllm-fuzzy2 versions
    <19.1R3-S9; 19.2 <19.2R3-S6; 19.3 <19.3R3-S7; 19.4 <19.4R3-S9; 20.2 <20.2R3-S5; 20.3 <20.3R3-S4; 20.4 <20.4R3-S4; 21.1 <21.1R3-S1; 21.2 <21.2R3; 21.3 <21.3R2; 21.4 <21.4R2+ 1 more
    • (no CPE)range: <19.1R3-S9; 19.2 <19.2R3-S6; 19.3 <19.3R3-S7; 19.4 <19.4R3-S9; 20.2 <20.2R3-S5; 20.3 <20.3R3-S4; 20.4 <20.4R3-S4; 21.1 <21.1R3-S1; 21.2 <21.2R3; 21.3 <21.3R2; 21.4 <21.4R2
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.