CVE-2022-22211 Details
Description
A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved on PTX Series allows an unprivileged attacker to cause Denial of Service (DoS). Continuously polling the SNMP jnxCosQstatTable causes the FPC to run out of GUID space, causing a Denial of Service to the FPC resources. When the FPC runs out of the GUID space, you will see the following syslog messages. The evo-aftmand-bt process is asserting. fpc1 evo-aftmand-bt[17556]: %USER-3: get_next_guid: Ran out of Guid Space start 1748051689472 end 1752346656767 fpc1 audit[17556]: %AUTH-5: ANOM_ABEND auid=4294967295 uid=0 gid=0 ses=4294967295 pid=17556 comm="EvoAftManBt-mai" exe="/usr/sbin/evo-aftmand-bt" sig=6 fpc1 kernel: %KERN-5: audit: type=1701 audit(1648567505.119:57): auid=4294967295 uid=0 gid=0 ses=4294967295 pid=17556 comm="EvoAftManBt-mai" exe="/usr/sbin/evo-aftmand-bt" sig=6 fpc1 emfd-fpa[14438]: %USER-5: Alarm set: APP color=red, class=CHASSIS, reason=Application evo-aftmand-bt fail on node Fpc1 fpc1 emfd-fpa[14438]: %USER-3-EMF_FPA_ALARM_REP: RaiseAlarm: Alarm(Location: /Chassis[0]/Fpc[1] Module: sysman Object: evo-aftmand-bt:0 Error: 2) reported fpc1 sysepochman[12738]: %USER-5-SYSTEM_REBOOT_EVENT: Reboot [node] [ungraceful reboot] [evo-aftmand-bt exited] The FPC resources can be monitored using the following commands: user@router> start shell [vrf:none] user@router-re0:~$ cli -c "show platform application-info allocations app evo-aftmand-bt" | grep ^fpc | grep -v Route | grep -i -v Nexthop | awk '{total[$1] += $5} END { for (key in total) { print key " " total[key]/4294967296 }}' Once the FPCs become unreachable they must be manually restarted as they do not self-recover. This issue affects Juniper Networks Junos OS Evolved on PTX Series: All versions prior to 20.4R3-S4-EVO; 21.1-EVO version 21.1R1-EVO and later versions; 21.2-EVO version 21.2R1-EVO and later versions; 21.3-EVO versions prior to 21.3R3-EVO; 21.4-EVO versions prior to 21.4R2-EVO; 22.1-EVO versions prior to 22.1R2-EVO.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA69916 | CVE | Permissions Required |
| https://kb.juniper.net/JSA69916 | [email protected] | Permissions Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos os evolved | < 20.4 20.4 - 20.4 r1 20.4 r1-s1 20.4 r1-s2 20.4 r2 20.4 r2-s1 20.4 r2-s2 20.4 r2-s3 20.4 r3 20.4 r3-s1 20.4 r3-s2 20.4 r3-s3 21.1 - 21.1 r1 21.1 r1-s1 21.1 r2 21.1 r3 21.1 r3-s1 21.2 - 21.2 r1 21.2 r1-s1 21.2 r1-s2 21.2 r2 21.2 r2-s1 21.2 r2-s2 21.2 r3 21.3 - 21.3 r1 21.3 r1-s1 21.3 r2 21.3 r2-s1 21.3 r2-s2 21.4 - 21.4 r1 21.4 r1-s1 21.4 r1-s2 22.1 r1 22.1 r1-s1 22.1 r1-s2 |
CPE
Remediation
| |
| juniper ptx1000 | All versions |
CPE
Remediation
| |
| juniper ptx1000-72q | All versions |
CPE
Remediation
| |
| juniper ptx10000 | All versions |
CPE
Remediation
| |
| juniper ptx10001 | All versions |
CPE
Remediation
| |
| juniper ptx10001-36mr | All versions |
CPE
Remediation
| |
| juniper ptx100016 | All versions |
CPE
Remediation
| |
| juniper ptx10002 | All versions |
CPE
Remediation
| |
| juniper ptx10002-60c | All versions |
CPE
Remediation
| |
| juniper ptx10003 | All versions |
CPE
Remediation
| |
| juniper ptx10003 160c | All versions |
CPE
Remediation
| |
| juniper ptx10003 80c | All versions |
CPE
Remediation
| |
| juniper ptx10003 81cd | All versions |
CPE
Remediation
| |
| juniper ptx10004 | All versions |
CPE
Remediation
| |
| juniper ptx10008 | All versions |
CPE
Remediation
| |
| juniper ptx10016 | All versions |
CPE
Remediation
| |
| juniper ptx3000 | All versions |
CPE
Remediation
| |
| juniper ptx5000 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 21, 2022 | Initial Analysis | [email protected] |