CVE-2022-22191
A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in Juniper Networks Junos OS on the EX4300 switch, sent from the local broadcast domain, may allow an unauthenticated network-adjacent attacker to trigger a PFEMAN watchdog timeout, causing the Packet Forwarding Engine (PFE) to crash and restart. After the restart, transit traffic will be temporarily interrupted until the PFE is reprogrammed. In a virtual chassis (VC), the impacted Flexible PIC Concentrator (FPC) may split from the VC temporarily, and join back into the VC once the PFE restarts. Continued receipt and processing of these packets will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks Junos OS on the EX4300: All versions prior to 15.1R7-S12; 18.4 versions prior to 18.4R2-S10, 18.4R3-S11; 19.1 versions prior to 19.1R3-S8; 19.2 versions prior to 19.2R1-S9, 19.2R3-S4; 19.3 versions prior to 19.3R3-S5; 19.4 versions prior to 19.4R2-S6, 19.4R3-S7; 20.1 versions prior to 20.1R3-S3; 20.2 versions prior to 20.2R3-S3; 20.3 versions prior to 20.3R3-S2; 20.4 versions prior to 20.4R3-S1; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R2-S1, 21.2R3; 21.3 versions prior to 21.3R1-S2, 21.3R2.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.20%
- CWE
- CWE-410
- Published
- 2022-04-14
- Last modified
- 2026-03-13
Affected products
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
Weakness type
Related vulnerabilities
- CVE-2021-1615 — Cisco Embedded Wireless Controller Software for Catalyst Access Points Denial of Service Vulnerability
- CVE-2022-2048 — In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug
- CVE-2019-0056 — Junos OS: MX Series: An MPC10 Denial of Service (DoS) due to OSPF states transitioning to Down, causes traffic to stop forwarding through the device.
- CVE-2023-38505 — DietPi-Dashboard Insufficient TLS Handshake Pool
- CVE-2025-41653 — Weidmueller: Denial-of-Service Vulnerability in the web server functionality of Industrial Ethernet Switches
- CVE-2022-46679 — Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthent
- CVE-2025-20103 — Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user
- CVE-2022-40224 — A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Swi