CVE-2022-22234 is an Improper Preservation of Consistency vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS, affecting EX2300 and EX3400 Series devices across numerous versions. A low-privileged, locally authenticated attacker can trigger a Denial of Service (DoS) by causing SFPs to be erroneously detected as unplugged during periods of high system activity. This leads to traffic impact and partial DoS, with the system recovering once activity subsides. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity and requiring low privileges, resulting in high availability impact. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
18.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:18.4:-:*:*:*:*:*:* | ||
18.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:18.4:r1:*:*:*:*:*:* | ||
18.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:18.4:r1-s1:*:*:*:*:*:* | ||
18.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:18.4:r1-s2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.