Metrics
No CVSS v4.0
Attack Vector Adjacent Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
User Interaction None
No CVSS v3.0
Access Vector Adjacent Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
This CVE is not in the KEV list.
The EPSS score is 0.00195.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Juniper |
|
Configuration 1 [-]
AND |
|
No data.
No data.
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-27307 | An Unchecked Error Condition vulnerability in the subscriber management daemon (smgd) of Juniper Networks Junos OS allows an unauthenticated adjacent attacker to cause a crash of and thereby a Denial of Service (DoS). In a subscriber management / broadband edge environment if a single session group configuration contains dual-stack and a pp0 interface, smgd will crash and restart every time a PPPoE client sends a specific message. This issue affects Juniper Networks Junos OS on MX Series: 16.1 version 16.1R1 and later versions prior to 18.4R3-S10; 19.1 versions prior to 19.1R2-S3, 19.1R3-S7; 19.2 versions prior to 19.2R1-S8, 19.2R3-S4; 19.3 versions prior to 19.3R3-S4; 19.4 versions prior to 19.4R3-S5; 20.1 versions prior to 20.1R3-S3; 20.2 versions prior to 20.2R3-S3; 20.3 versions prior to 20.3R3-S2; 20.4 versions prior to 20.4R3; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R2. This issue does not affect Juniper Networks Junos OS versions prior to 16.1R1. |
Solution
The following software releases have been updated to resolve this specific issue: 18.4R3-S10, 19.1R2-S3, 19.1R3-S7, 19.2R1-S8, 19.2R3-S4, 19.3R3-S4, 19.4R3-S5, 20.1R3-S3, 20.2R3-S3, 20.3R3-S2, 20.4R3, 21.1R3, 21.2R2, 21.3R1, and all subsequent releases.
Workaround
Remove the pp0 interface from a DHCPv6 dual-stack group and move to its own group with no dual-stack enabled. user@device# show system services dhcp-local-server dhcpv6 ... group <group-name1> { overrides { ... dual-stack <dual-stack-group-name>; } ... interface pp0.0; <<<<< delete and add to new group ... } group <group-name2> { <<<<< new group for PP0 interfaces to be handled separately. ... interface pp0.0; <<<<< ... }
Link | Providers |
---|---|
https://kb.juniper.net/JSA11268 |
![]() ![]() |
No history.

Status: PUBLISHED
Assigner: juniper
Published:
Updated: 2024-09-17T03:59:29.486Z
Reserved: 2021-12-21T00:00:00
Link: CVE-2022-22160

No data.

Status : Modified
Published: 2022-01-19T01:15:08.557
Modified: 2024-11-21T06:46:16.993
Link: CVE-2022-22160

No data.

No data.