Search

Find a vulnerability

Search criteria

    24 vulnerabilities by juniper_networks

    CVE-2024-21598 (GCVE-0-2024-21598)

    Vulnerability from nvd โ€“ Published: 2024-04-12 14:54 โ€“ Updated: 2024-08-01 22:27
    VLAI
    Title
    Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash
    Summary
    An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute with a specifically malformed TLV, rpd will crash and restart. This issue affects Juniper Networks Junos OS: * 20.4 versions 20.4R1 and later versions earlier than 20.4R3-S9; * 21.2 versions earlier than 21.2R3-S7; * 21.3 versions earlier than 21.3R3-S5; * 21.4 versions earlier than 21.4R3-S5; * 22.1 versions earlier than 22.1R3-S4; * 22.2 versions earlier than 22.2R3-S3; * 22.3 versions earlier than 22.3R3-S1; * 22.4 versions earlier than 22.4R3; * 23.2 versions earlier than 23.2R1-S2, 23.2R2; Junos OS Evolved: * 20.4-EVO versions 20.4R1-EVO and later versions earlier than 20.4R3-S9-EVO; * 21.2-EVO versions earlier than 21.2R3-S7-EVO; * 21.3-EVO versions earlier than 21.3R3-S5-EVO; * 21.4-EVO versions earlier than 21.4R3-S5-EVO; * 22.1-EVO versions earlier than 22.1R3-S4-EVO; * 22.2-EVO versions earlier than 22.2R3-S3-EVO; * 22.3-EVO versions earlier than 22.3R3-S1-EVO; * 22.4-EVO versions earlier than 22.4R3-EVO; * 23.2-EVO versions earlier than 23.2R1-S2-EVO, 23.2R2-EVO; This issue does not affect Juniper Networks * Junos OS versions earlier than 20.4R1; * Junos OS Evolved versions earlier than 20.4R1-EVO. This is a related but separate issue than the one described in JSA79095.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-04-12 18:02 UTC
    CWE
    • CWE-1286 - Improper Validation of Syntactic Correctness of Input
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 20.4 , < 20.4R3-S9 (semver)
    Affected: 21.2 , < 21.2R3-S7 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3-S5 (semver)
    Affected: 22.1 , < 22.1R3-S4 (semver)
    Affected: 22.2 , < 22.2R3-S3 (semver)
    Affected: 22.3 , < 22.3R3-S1 (semver)
    Affected: 22.4 , < 22.4R3 (semver)
    Affected: 23.2 , < 23.2R1-S2, 23.2R2 (semver)
    Create a notification for this product.
    Juniper Networks Junos OS Evolved Affected: 20.4-EVO , < 20.4R3-S9-EVO (semver)
    Affected: 21.2-EVO , < 21.2R3-S7-EVO (semver)
    Affected: 21.3-EVO , < 21.3R3-S5-EVO (semver)
    Affected: 21.4-EVO , < 21.4R3-S5-EVO (semver)
    Affected: 22.1-EVO , < 22.1R3-S4-EVO (semver)
    Affected: 22.2-EVO , < 22.2R3-S3-EVO (semver)
    Affected: 22.3-EVO , < 22.3R3-S1-EVO (semver)
    Affected: 22.4-EVO , < 22.4R3-EVO (semver)
    Affected: 23.2-EVO , < 23.2R1-S2-EVO, 23.2R2-EVO (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 20.4 , < 20.4r3-s9 (custom)
    Affected: 21.2 , < 21.2r3-s7 (custom)
    Affected: 21.3 , < 21.3r3-s5 (custom)
    Affected: 21.4 , < 21.4r3-s5 (custom)
    Affected: 22.1 , < 22.1r3-s4 (custom)
    Affected: 22.2 , < 22.2r3-s3 (custom)
    Affected: 22.3 , < 22.3r3-s1 (custom)
    Affected: 22.4 , < 22.4r3 (custom)
    Affected: 23.2 , < 23.2r1-s2 (custom)
        cpe:2.3:o:juniper_networks:junos_os:20.4:*:*:*:*:*:*:*
    Create a notification for this product.
    juniper junos_os_evolved Affected: 20.4 , < 20.4r3-s9 (custom)
    Affected: 21.2 , < 21.2r3-s7 (custom)
    Affected: 21.3 , < 21.3r3-s5 (custom)
    Affected: 21.4 , < 21.4r3-s4 (custom)
    Affected: 22.1 , < 22.1r3-s4 (custom)
    Affected: 22.2 , < 22.2r3-s3 (custom)
        cpe:2.3:o:juniper:junos_os_evolved:22.3:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:22.4:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:23.2:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:20.4:r1:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:21.2:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:21.3:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:21.4:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:22.1:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:22.2:-:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-04-10 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:20.4:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4r3-s9",
                    "status": "affected",
                    "version": "20.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2r3-s7",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.3r3-s5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.4r3-s5",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1r3-s4",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.2r3-s3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3r3-s1",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4r3",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "23.2r1-s2",
                    "status": "affected",
                    "version": "23.2",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:juniper:junos_os_evolved:22.3:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:22.4:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:23.2:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:20.4:r1:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:21.2:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:21.3:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:21.4:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:22.1:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:22.2:-:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os_evolved",
                "vendor": "juniper",
                "versions": [
                  {
                    "lessThan": "20.4r3-s9",
                    "status": "affected",
                    "version": "20.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2r3-s7",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.3r3-s5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.4r3-s4",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1r3-s4",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.2r3-s3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-21598",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-12T18:02:57.570562Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-31T14:32:30.418Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T22:27:36.007Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "http://supportportal.juniper.net/JSA75739"
              },
              {
                "tags": [
                  "technical-description",
                  "x_transferred"
                ],
                "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S9",
                  "status": "affected",
                  "version": "20.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S7",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S5",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S4",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3-S3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R3-S1",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R3",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "23.2R1-S2, 23.2R2",
                  "status": "affected",
                  "version": "23.2",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Junos OS Evolved",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S9-EVO",
                  "status": "affected",
                  "version": "20.4-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S7-EVO",
                  "status": "affected",
                  "version": "21.2-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5-EVO",
                  "status": "affected",
                  "version": "21.3-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S5-EVO",
                  "status": "affected",
                  "version": "21.4-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S4-EVO",
                  "status": "affected",
                  "version": "22.1-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3-S3-EVO",
                  "status": "affected",
                  "version": "22.2-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R3-S1-EVO",
                  "status": "affected",
                  "version": "22.3-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R3-EVO",
                  "status": "affected",
                  "version": "22.4-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "23.2R1-S2-EVO, 23.2R2-EVO",
                  "status": "affected",
                  "version": "23.2-EVO",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTo be exposed to this vulnerability BGP needs to be configured as in the following example, but no further options need to be enabled:\u003c/p\u003e\u003cp\u003e\u0026nbsp; [ protocols bgp group \u0026lt;group\u0026gt; neighbor ... ]\u003c/p\u003e"
                }
              ],
              "value": "To be exposed to this vulnerability BGP needs to be configured as in the following example, but no further options need to be enabled:\n\n\u00a0 [ protocols bgp group \u003cgroup\u003e neighbor ... ]"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Juniper SIRT would like to acknowledge and thank Matteo Memelli from Amazon for responsibly reporting this vulnerability."
            }
          ],
          "datePublic": "2024-04-10T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).\u003cbr\u003e\u003cbr\u003eIf a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute with a specifically malformed TLV, rpd will crash and restart.\u003cbr\u003e\u003cbr\u003eThis issue affects Juniper Networks\u003cbr\u003eJunos OS:\u003cbr\u003e\u003cul\u003e\u003cli\u003e20.4 versions 20.4R1 and later versions earlier than 20.4R3-S9;\u003c/li\u003e\u003cli\u003e21.2 versions earlier than 21.2R3-S7;\u003c/li\u003e\u003cli\u003e21.3 versions earlier than 21.3R3-S5;\u003c/li\u003e\u003cli\u003e21.4 versions earlier than 21.4R3-S5;\u003c/li\u003e\u003cli\u003e22.1 versions earlier than 22.1R3-S4;\u003c/li\u003e\u003cli\u003e22.2 versions earlier than 22.2R3-S3;\u003c/li\u003e\u003cli\u003e22.3 versions earlier than 22.3R3-S1;\u003c/li\u003e\u003cli\u003e22.4 versions earlier than 22.4R3;\u003c/li\u003e\u003cli\u003e23.2 versions earlier than 23.2R1-S2, 23.2R2;\u003c/li\u003e\u003c/ul\u003e\u003cbr\u003eJunos OS Evolved:\u003cbr\u003e\u003cul\u003e\u003cli\u003e20.4-EVO versions 20.4R1-EVO and later versions earlier than 20.4R3-S9-EVO;\u003c/li\u003e\u003cli\u003e21.2-EVO versions earlier than 21.2R3-S7-EVO;\u003c/li\u003e\u003cli\u003e21.3-EVO versions earlier than 21.3R3-S5-EVO;\u003c/li\u003e\u003cli\u003e21.4-EVO versions earlier than 21.4R3-S5-EVO;\u003c/li\u003e\u003cli\u003e22.1-EVO versions earlier than 22.1R3-S4-EVO;\u003c/li\u003e\u003cli\u003e22.2-EVO versions earlier than 22.2R3-S3-EVO;\u003c/li\u003e\u003cli\u003e22.3-EVO versions earlier than 22.3R3-S1-EVO;\u003c/li\u003e\u003cli\u003e22.4-EVO versions earlier than 22.4R3-EVO;\u003c/li\u003e\u003cli\u003e23.2-EVO versions earlier than 23.2R1-S2-EVO, 23.2R2-EVO;\u003c/li\u003e\u003c/ul\u003e\u003cbr\u003eThis issue does not affect Juniper Networks\u003cbr\u003e\u003cul\u003e\u003cli\u003eJunos OS versions earlier than 20.4R1;\u003c/li\u003e\u003cli\u003eJunos OS Evolved versions earlier than 20.4R1-EVO.\u003c/li\u003e\u003c/ul\u003e\u003cbr\u003eThis is a related but separate issue than the one described in JSA79095.\u003cbr\u003e"
                }
              ],
              "value": "An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).\n\nIf a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute with a specifically malformed TLV, rpd will crash and restart.\n\nThis issue affects Juniper Networks\nJunos OS:\n  *  20.4 versions 20.4R1 and later versions earlier than 20.4R3-S9;\n  *  21.2 versions earlier than 21.2R3-S7;\n  *  21.3 versions earlier than 21.3R3-S5;\n  *  21.4 versions earlier than 21.4R3-S5;\n  *  22.1 versions earlier than 22.1R3-S4;\n  *  22.2 versions earlier than 22.2R3-S3;\n  *  22.3 versions earlier than 22.3R3-S1;\n  *  22.4 versions earlier than 22.4R3;\n  *  23.2 versions earlier than 23.2R1-S2, 23.2R2;\n\n\n\nJunos OS Evolved:\n  *  20.4-EVO versions 20.4R1-EVO and later versions earlier than 20.4R3-S9-EVO;\n  *  21.2-EVO versions earlier than 21.2R3-S7-EVO;\n  *  21.3-EVO versions earlier than 21.3R3-S5-EVO;\n  *  21.4-EVO versions earlier than 21.4R3-S5-EVO;\n  *  22.1-EVO versions earlier than 22.1R3-S4-EVO;\n  *  22.2-EVO versions earlier than 22.2R3-S3-EVO;\n  *  22.3-EVO versions earlier than 22.3R3-S1-EVO;\n  *  22.4-EVO versions earlier than 22.4R3-EVO;\n  *  23.2-EVO versions earlier than 23.2R1-S2-EVO, 23.2R2-EVO;\n\n\n\nThis issue does not affect Juniper Networks\n  *  Junos OS versions earlier than 20.4R1;\n  *  Junos OS Evolved versions earlier than 20.4R1-EVO.\n\n\n\nThis is a related but separate issue than the one described in JSA79095."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1286",
                  "description": "CWE-1286 Improper Validation of Syntactic Correctness of Input",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-16T19:53:00.228Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "http://supportportal.juniper.net/JSA75739"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: \u003c/p\u003e\u003cp\u003eJunos OS: 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S3, 22.3R3-S1, 22.4R3, 23.2R1-S2, 23.2R2, 23.4R1, and all subsequent releases;\u003c/p\u003e\u003cp\u003eJunos OS Evolved: 20.4R3-S9-EVO, 21.2R3-S7-EVO, 21.3R3-S5-EVO, 21.4R3-S5-EVO, 22.1R3-S4-EVO, 22.2R3-S3-EVO, 22.3R3-S1-EVO, 22.4R3-EVO, 23.2R1-S2-EVO, 23.2R2-EVO, 23.4R1-EVO, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: \n\nJunos OS: 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S3, 22.3R3-S1, 22.4R3, 23.2R1-S2, 23.2R2, 23.4R1, and all subsequent releases;\n\nJunos OS Evolved: 20.4R3-S9-EVO, 21.2R3-S7-EVO, 21.3R3-S5-EVO, 21.4R3-S5-EVO, 22.1R3-S4-EVO, 22.2R3-S3-EVO, 22.3R3-S1-EVO, 22.4R3-EVO, 23.2R1-S2-EVO, 23.2R2-EVO, 23.4R1-EVO, and all subsequent releases."
            }
          ],
          "source": {
            "advisory": "JSA75739",
            "defect": [
              "1760356"
            ],
            "discovery": "USER"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-04-10T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThere are no known workarounds for this issue.\u003c/p\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2024-21598",
        "datePublished": "2024-04-12T14:54:23.761Z",
        "dateReserved": "2023-12-27T19:38:25.705Z",
        "dateUpdated": "2024-08-01T22:27:36.007Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-44199 (GCVE-0-2023-44199)

    Vulnerability from nvd โ€“ Published: 2023-10-12 23:05 โ€“ Updated: 2024-09-18 14:33
    VLAI
    Title
    Junos OS: MX Series: In a PTP scenario a prolonged routing protocol churn can trigger an FPC reboot
    Summary
    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). On Junos MX Series platforms with Precision Time Protocol (PTP) configured, a prolonged routing protocol churn can lead to an FPC crash and restart. This issue affects Juniper Networks Junos OS on MX Series: * All versions prior to 20.4R3-S4; * 21.1 version 21.1R1 and later versions; * 21.2 versions prior to 21.2R3-S2; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3; * 22.1 versions prior to 22.1R3; * 22.2 versions prior to 22.2R1-S1, 22.2R2.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-09-18 14:33 UTC
    CWE
    • CWE-754 - Improper Check for Unusual or Exceptional Conditions
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 0 , < 20.4R3-S4 (semver)
    Affected: 21.1R1 , < 21.1* (semver)
    Affected: 21.2 , < 21.2R3-S2 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3 (semver)
    Affected: 22.1 , < 22.1R3 (semver)
    Affected: 22.2 , < 22.2R1-S1, 22.2R2 (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 20.4r3-s4 (semver)
    Affected: 21.1r1 , < 21.1* (semver)
    Affected: 21.2 , < 21.2r3-s2 (semver)
    Affected: 21.3 , < 21.3r3-s5 (semver)
    Affected: 21.4 , < 21.4r3 (semver)
    Affected: 22.1 , < 22.1r3 (semver)
    Affected: 22.2 , < 22.2r1-s1,22.2r2 (semver)
        cpe:2.3:a:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-10-11 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:59:51.383Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA73165"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4r3-s4",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.1*",
                    "status": "affected",
                    "version": "21.1r1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2r3-s2",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3r3-s5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4r3",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1r3",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r1-s1,22.2r2",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-44199",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-18T14:33:42.839560Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T14:33:48.227Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "MX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.1*",
                  "status": "affected",
                  "version": "21.1R1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S2",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R1-S1, 22.2R2",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTo be exposed to this issue an FPC must have at least one interface with PTP configured like in the following example:\u003c/p\u003e \u003ctt\u003e[ protocols ptp master/slave interface ]\u003c/tt\u003e"
                }
              ],
              "value": "To be exposed to this issue an FPC must have at least one interface with PTP configured like in the following example:\n\n [ protocols ptp master/slave interface ]"
            }
          ],
          "datePublic": "2023-10-11T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eAn Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).\u003c/p\u003e\u003cp\u003eOn Junos MX Series platforms with Precision Time Protocol (PTP) configured, a prolonged routing protocol churn can lead to an FPC crash and restart.\u003c/p\u003e\u003cp\u003eThis issue affects Juniper Networks Junos OS on MX Series:\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003eAll versions prior to 20.4R3-S4;\u003c/li\u003e\u003cli\u003e21.1 version 21.1R1 and later versions;\u003c/li\u003e\u003cli\u003e21.2 versions prior to 21.2R3-S2;\u003c/li\u003e\u003cli\u003e21.3 versions prior to 21.3R3-S5;\u003c/li\u003e\u003cli\u003e21.4 versions prior to 21.4R3;\u003c/li\u003e\u003cli\u003e22.1 versions prior to 22.1R3;\u003c/li\u003e\u003cli\u003e22.2 versions prior to 22.2R1-S1, 22.2R2.\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e\n\n"
                }
              ],
              "value": "\nAn Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).\n\nOn Junos MX Series platforms with Precision Time Protocol (PTP) configured, a prolonged routing protocol churn can lead to an FPC crash and restart.\n\nThis issue affects Juniper Networks Junos OS on MX Series:\n\n\n\n  *  All versions prior to 20.4R3-S4;\n  *  21.1 version 21.1R1 and later versions;\n  *  21.2 versions prior to 21.2R3-S2;\n  *  21.3 versions prior to 21.3R3-S5;\n  *  21.4 versions prior to 21.4R3;\n  *  22.1 versions prior to 22.1R3;\n  *  22.2 versions prior to 22.2R1-S1, 22.2R2.\n\n\n\n\n\n\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-754",
                  "description": "CWE-754 Improper Check for Unusual or Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-12T23:05:52.303Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.juniper.net/JSA73165"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S4, 21.2R3-S2, 21.3R3-S5, 21.4R3, 22.1R3, 22.2R1-S1, 22.2R2, 22.3R1, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S4, 21.2R3-S2, 21.3R3-S5, 21.4R3, 22.1R3, 22.2R1-S1, 22.2R2, 22.3R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "advisory": "JSA73165",
            "defect": [
              "1653681"
            ],
            "discovery": "USER"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-10-11T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS: MX Series: In a PTP scenario a prolonged routing protocol churn can trigger an FPC reboot",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThere are no known workarounds for this issue.\u003c/p\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-44199",
        "datePublished": "2023-10-12T23:05:52.303Z",
        "dateReserved": "2023-09-26T19:30:32.350Z",
        "dateUpdated": "2024-09-18T14:33:48.227Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-44198 (GCVE-0-2023-44198)

    Vulnerability from nvd โ€“ Published: 2023-10-12 23:05 โ€“ Updated: 2024-09-18 14:41
    VLAI
    Title
    Junos OS: SRX Series and MX Series: SIP ALG doesn't drop specifically malformed retransmitted SIP packets
    Summary
    An Improper Check for Unusual or Exceptional Conditions vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated network-based attacker to cause an integrity impact in connected networks. If the SIP ALG is configured and a device receives a specifically malformed SIP packet, the device prevents this packet from being forwarded, but any subsequently received retransmissions of the same packet are forwarded as if they were valid. This issue affects Juniper Networks Junos OS on SRX Series and MX Series: * 20.4 versions prior to 20.4R3-S5; * 21.1 versions prior to 21.1R3-S4; * 21.2 versions prior to 21.2R3-S4; * 21.3 versions prior to 21.3R3-S3; * 21.4 versions prior to 21.4R3-S2; * 22.1 versions prior to 22.1R2-S2, 22.1R3; * 22.2 versions prior to 22.2R2-S1, 22.2R3; * 22.3 versions prior to 22.3R1-S2, 22.3R2. This issue doesn't not affected releases prior to 20.4R1.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-09-18 14:36 UTC
    CWE
    • CWE-754 - Improper Check for Unusual or Exceptional Conditions
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 20.4 , < 20.4R3-S5 (semver)
    Affected: 21.1 , < 21.1R3-S4 (semver)
    Affected: 21.2 , < 21.2R3-S4 (semver)
    Affected: 21.3 , < 21.3R3-S3 (semver)
    Affected: 21.4 , < 21.4R3-S2 (semver)
    Affected: 22.1 , < 22.1R2-S2, 22.1R3 (semver)
    Affected: 22.2 , < 22.2R2-S1, 22.2R3 (semver)
    Affected: 22.3 , < 22.3R1-S2, 22.3R2 (semver)
    Affected: 0 , < 20.4R1 (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 20.4 , < 20.4r3-s5 (semver)
    Affected: 21.1 , < 21.1r3-s4 (semver)
    Affected: 21.2 , < 21.2r3-s4 (semver)
    Affected: 21.3 , < 21.3r3-s3 (semver)
    Affected: 21.4 , < 21.4r3-s2 (semver)
    Affected: 22.1 , < 22.1r2-s2,22.1r3 (semver)
    Affected: 22.2 , < 22.2r2-s122.2r3 (semver)
    Affected: 22.3 , < 22.3r1-s2.22.3r2 (semver)
    Affected: 0 , < 20.4r1 (semver)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-10-11 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:59:51.680Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA73164"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4r3-s5",
                    "status": "affected",
                    "version": "20.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.1r3-s4",
                    "status": "affected",
                    "version": "21.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2r3-s4",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3r3-s3",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4r3-s2",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1r2-s2,22.1r3",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r2-s122.2r3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r1-s2.22.3r2",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "20.4r1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-44198",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-18T14:36:59.623824Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T14:41:11.841Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "SRX Series",
                "MX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S5",
                  "status": "affected",
                  "version": "20.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.1R3-S4",
                  "status": "affected",
                  "version": "21.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S4",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S3",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S2",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R2-S2, 22.1R3",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R2-S1, 22.2R3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R1-S2, 22.3R2",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "20.4R1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eTo be affected the SIP ALG needs to be enabled, either implicitly / by default or by way of configuration. Please verify on SRX, and MX with SPC3 with:\u003c/p\u003e\u003ccode\u003euser@host\u0026gt; show security alg status | match sip\u003c/code\u003e\u003cbr\u003e\u003ccode\u003eSIP : Enabled\u003c/code\u003e\u003cbr\u003e\u003cp\u003ePlease verify on MX whether the following is configured:\u003c/p\u003e\u003ccode\u003e[ services ... rule \u0026lt;rule-name\u0026gt; (term \u0026lt;term-name\u0026gt; ) from/match application/application-set \u0026lt;name\u0026gt; ]\u003c/code\u003e\u003cbr\u003e\u003cp\u003ewhere either\u003c/p\u003e\u003ccode\u003ea. name = junos-sip or\u003c/code\u003e\u003cbr\u003e\u003cp\u003ean application or application-set refers to SIP:\u003c/p\u003e\u003ccode\u003eb. [ applications application \u0026lt;name\u0026gt; application-protocol sip ] or\u003c/code\u003e\u003cbr\u003e\u003ccode\u003ec. [ applications application-set \u0026lt;name\u0026gt; application junos-sip ]\u003c/code\u003e\n\n"
                }
              ],
              "value": "\nTo be affected the SIP ALG needs to be enabled, either implicitly / by default or by way of configuration. Please verify on SRX, and MX with SPC3 with:\n\nuser@host\u003e show security alg status | match sip\nSIP : Enabled\nPlease verify on MX whether the following is configured:\n\n[ services ... rule \u003crule-name\u003e (term \u003cterm-name\u003e ) from/match application/application-set \u003cname\u003e ]\nwhere either\n\na. name = junos-sip or\nan application or application-set refers to SIP:\n\nb. [ applications application \u003cname\u003e application-protocol sip ] or\nc. [ applications application-set \u003cname\u003e application junos-sip ]\n\n"
            }
          ],
          "datePublic": "2023-10-11T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eAn Improper Check for Unusual or Exceptional Conditions vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated network-based attacker to cause an integrity impact in connected networks.\u003c/p\u003e\u003cp\u003eIf the SIP ALG is configured and a device receives a specifically malformed SIP packet, the device prevents this packet from being forwarded, but any subsequently received retransmissions of the same packet are forwarded as if they were valid.\u003c/p\u003e\u003cp\u003eThis issue affects Juniper Networks Junos OS on SRX Series and MX Series:\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003e20.4 versions prior to 20.4R3-S5;\u003c/li\u003e\u003cli\u003e21.1 versions prior to 21.1R3-S4;\u003c/li\u003e\u003cli\u003e21.2 versions prior to 21.2R3-S4;\u003c/li\u003e\u003cli\u003e21.3 versions prior to 21.3R3-S3;\u003c/li\u003e\u003cli\u003e21.4 versions prior to 21.4R3-S2;\u003c/li\u003e\u003cli\u003e22.1 versions prior to 22.1R2-S2, 22.1R3;\u003c/li\u003e\u003cli\u003e22.2 versions prior to 22.2R2-S1, 22.2R3;\u003c/li\u003e\u003cli\u003e22.3 versions prior to 22.3R1-S2, 22.3R2.\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eThis issue doesn\u0027t not affected releases prior to 20.4R1.\u003c/p\u003e\n\n"
                }
              ],
              "value": "\nAn Improper Check for Unusual or Exceptional Conditions vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated network-based attacker to cause an integrity impact in connected networks.\n\nIf the SIP ALG is configured and a device receives a specifically malformed SIP packet, the device prevents this packet from being forwarded, but any subsequently received retransmissions of the same packet are forwarded as if they were valid.\n\nThis issue affects Juniper Networks Junos OS on SRX Series and MX Series:\n\n\n\n  *  20.4 versions prior to 20.4R3-S5;\n  *  21.1 versions prior to 21.1R3-S4;\n  *  21.2 versions prior to 21.2R3-S4;\n  *  21.3 versions prior to 21.3R3-S3;\n  *  21.4 versions prior to 21.4R3-S2;\n  *  22.1 versions prior to 22.1R2-S2, 22.1R3;\n  *  22.2 versions prior to 22.2R2-S1, 22.2R3;\n  *  22.3 versions prior to 22.3R1-S2, 22.3R2.\n\n\n\n\nThis issue doesn\u0027t not affected releases prior to 20.4R1.\n\n\n\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-754",
                  "description": "CWE-754 Improper Check for Unusual or Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-12T23:05:42.031Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.juniper.net/JSA73164"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S5, 21.1R3-S4, 21.2R3-S4, 21.3R3-S3, 21.4R3-S2, 22.1R2-S2, 22.1R3, 22.2R2-S1, 22.2R3, 22.3R1-S2, 22.3R2, 22.4R1, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S5, 21.1R3-S4, 21.2R3-S4, 21.3R3-S3, 21.4R3-S2, 22.1R2-S2, 22.1R3, 22.2R2-S1, 22.2R3, 22.3R1-S2, 22.3R2, 22.4R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "advisory": "JSA73164",
            "defect": [
              "1693379"
            ],
            "discovery": "INTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-10-11T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS: SRX Series and MX Series: SIP ALG doesn\u0027t drop specifically malformed retransmitted SIP packets",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThere are no known workarounds for this issue.\u003c/p\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-44198",
        "datePublished": "2023-10-12T23:05:42.031Z",
        "dateReserved": "2023-09-26T19:30:32.350Z",
        "dateUpdated": "2024-09-18T14:41:11.841Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-44192 (GCVE-0-2023-44192)

    Vulnerability from nvd โ€“ Published: 2023-10-12 23:03 โ€“ Updated: 2024-09-18 14:21
    VLAI
    Title
    Junos OS: QFX5000 Series: DMA memory leak is observed when specific DHCP packets are transmitted over pseudo-VTEP
    Summary
    An Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause memory leak, leading to Denial of Service (DoS). On all Junos OS QFX5000 Series platforms, when pseudo-VTEP (Virtual Tunnel End Point) is configured under EVPN-VXLAN scenario, and specific DHCP packets are transmitted, DMA memory leak is observed. Continuous receipt of these specific DHCP packets will cause memory leak to reach 99% and then cause the protocols to stop working and traffic is impacted, leading to Denial of Service (DoS) condition. A manual reboot of the system recovers from the memory leak. To confirm the memory leak, monitor for "sheaf:possible leak" and "vtep not found" messages in the logs. This issue affects: Juniper Networks Junos OS QFX5000 Series: * All versions prior to 20.4R3-S6; * 21.1 versions prior to 21.1R3-S5; * 21.2 versions prior to 21.2R3-S5; * 21.3 versions prior to 21.3R3-S4; * 21.4 versions prior to 21.4R3-S3; * 22.1 versions prior to 22.1R3-S2; * 22.2 versions prior to 22.2R2-S2, 22.2R3; * 22.3 versions prior to 22.3R2-S1, 22.3R3; * 22.4 versions prior to 22.4R1-S2, 22.4R2.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-09-18 14:03 UTC
    CWE
    • CWE-20 - Improper Input Validation
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 0 , < 20.4R3-S6 (semver)
    Affected: 21.1 , < 21.1R3-S5 (semver)
    Affected: 21.2 , < 21.2R3-S5 (semver)
    Affected: 21.3 , < 21.3R3-S4 (semver)
    Affected: 21.4 , < 21.4R3-S3 (semver)
    Affected: 22.1 , < 22.1R3-S2 (semver)
    Affected: 22.2 , < 22.2R2-S2, 22.2R3 (semver)
    Affected: 22.3 , < 22.3R2-S1, 22.3R3 (semver)
    Affected: 22.4 , < 22.4R1-S2, 22.4R2 (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 20.4r3-s6 (semver)
    Affected: 21.1 , < 21.1r3-s5 (semver)
    Affected: 21.2 , < 21.2r3-s5 (semver)
    Affected: 21.3 , < 21.3r3-s4 (semver)
    Affected: 21.4 , < 21.4r3-s3 (semver)
    Affected: 22.1 , < 22.1r3-s2 (semver)
    Affected: 22.2 , < 22.2r2-s2 (semver)
    Affected: 22.2 , < 22.2r3 (semver)
    Affected: 22.3 , < 22.3r2-s1 (custom)
    Affected: 22.3 , < 22..3r3 (custom)
    Affected: 22.4 , < 22.4r2-s2 (custom)
    Affected: 22.4 , < 22.4r2 (custom)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-10-11 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:59:51.573Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA73156"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4r3-s6",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.1r3-s5",
                    "status": "affected",
                    "version": "21.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2r3-s5",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3r3-s4",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4r3-s3",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1r3-s2",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r2-s2",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r2-s1",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22..3r3",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4r2-s2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4r2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-44192",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-18T14:03:43.315994Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T14:21:02.483Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "QFX5000 Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.1R3-S5",
                  "status": "affected",
                  "version": "21.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S5",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S4",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S3",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S2",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R2-S2, 22.2R3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R2-S1, 22.3R3",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R1-S2, 22.4R2",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eFor this issue to surface, shared tunnels need to be configured under EVPN-VXLAN scenario.\u003c/p\u003e\u003ctt\u003e[ forwarding-options evpn-vxlan shared-tunnels ]\u003c/tt\u003e"
                }
              ],
              "value": "For this issue to surface, shared tunnels need to be configured under EVPN-VXLAN scenario.\n\n[ forwarding-options evpn-vxlan shared-tunnels ]"
            }
          ],
          "datePublic": "2023-10-11T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eAn Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause memory leak, leading to Denial of Service (DoS).\u003c/p\u003e\u003cp\u003eOn all Junos OS QFX5000 Series platforms, when pseudo-VTEP (Virtual Tunnel End Point) is configured under EVPN-VXLAN scenario, and specific DHCP packets are transmitted, DMA memory leak is observed. Continuous receipt of these specific DHCP packets will cause memory leak to reach 99% and then cause the protocols to stop working and traffic is impacted, leading to Denial of Service (DoS) condition. A manual reboot of the system recovers from the memory leak.\u003c/p\u003e\u003cp\u003eTo confirm the memory leak, monitor for \"sheaf:possible leak\" and \"vtep not found\" messages in the logs.\u003c/p\u003e\u003cp\u003eThis issue affects:\u003c/p\u003e\u003cp\u003eJuniper Networks Junos OS QFX5000 Series:\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003eAll versions prior to 20.4R3-S6;\u003c/li\u003e\u003cli\u003e21.1 versions prior to 21.1R3-S5;\u003c/li\u003e\u003cli\u003e21.2 versions prior to 21.2R3-S5;\u003c/li\u003e\u003cli\u003e21.3 versions prior to 21.3R3-S4;\u003c/li\u003e\u003cli\u003e21.4 versions prior to 21.4R3-S3;\u003c/li\u003e\u003cli\u003e22.1 versions prior to 22.1R3-S2;\u003c/li\u003e\u003cli\u003e22.2 versions prior to 22.2R2-S2, 22.2R3;\u003c/li\u003e\u003cli\u003e22.3 versions prior to 22.3R2-S1, 22.3R3;\u003c/li\u003e\u003cli\u003e22.4 versions prior to 22.4R1-S2, 22.4R2.\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e\n\n"
                }
              ],
              "value": "\nAn Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause memory leak, leading to Denial of Service (DoS).\n\nOn all Junos OS QFX5000 Series platforms, when pseudo-VTEP (Virtual Tunnel End Point) is configured under EVPN-VXLAN scenario, and specific DHCP packets are transmitted, DMA memory leak is observed. Continuous receipt of these specific DHCP packets will cause memory leak to reach 99% and then cause the protocols to stop working and traffic is impacted, leading to Denial of Service (DoS) condition. A manual reboot of the system recovers from the memory leak.\n\nTo confirm the memory leak, monitor for \"sheaf:possible leak\" and \"vtep not found\" messages in the logs.\n\nThis issue affects:\n\nJuniper Networks Junos OS QFX5000 Series:\n\n\n\n  *  All versions prior to 20.4R3-S6;\n  *  21.1 versions prior to 21.1R3-S5;\n  *  21.2 versions prior to 21.2R3-S5;\n  *  21.3 versions prior to 21.3R3-S4;\n  *  21.4 versions prior to 21.4R3-S3;\n  *  22.1 versions prior to 22.1R3-S2;\n  *  22.2 versions prior to 22.2R2-S2, 22.2R3;\n  *  22.3 versions prior to 22.3R2-S1, 22.3R3;\n  *  22.4 versions prior to 22.4R1-S2, 22.4R2.\n\n\n\n\n\n\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-12T23:03:45.324Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.juniper.net/JSA73156"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S6, 21.1R3-S5, 21.2R3-S5, 21.3R3-S4, 21.4R3-S3, 22.1R3-S2, 22.2R2-S2, 22.2R3, 22.3R2-S1, 22.3R3, 22.4R1-S2, 22.4R2, 23.2R1, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S6, 21.1R3-S5, 21.2R3-S5, 21.3R3-S4, 21.4R3-S3, 22.1R3-S2, 22.2R2-S2, 22.2R3, 22.3R2-S1, 22.3R3, 22.4R1-S2, 22.4R2, 23.2R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "advisory": "JSA73156",
            "defect": [
              "1708370"
            ],
            "discovery": "USER"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-10-11T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS: QFX5000 Series: DMA memory leak is observed when specific DHCP packets are transmitted over pseudo-VTEP",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThere are no known workarounds for this issue.\u003c/p\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-44192",
        "datePublished": "2023-10-12T23:03:45.324Z",
        "dateReserved": "2023-09-26T19:30:27.954Z",
        "dateUpdated": "2024-09-18T14:21:02.483Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-44191 (GCVE-0-2023-44191)

    Vulnerability from nvd โ€“ Published: 2023-10-12 23:03 โ€“ Updated: 2024-09-19 14:14
    VLAI
    Title
    Junos OS: QFX5000 Series and EX4000 Series: Denial of Service (DoS) on a large scale VLAN due to PFE hogging
    Summary
    An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all Junos OS QFX5000 Series and EX4000 Series platforms, when a high number of VLANs are configured, a specific DHCP packet will cause PFE hogging which will lead to dropping of socket connections. This issue affects: Juniper Networks Junos OS on QFX5000 Series and EX4000 Series * 21.1 versions prior to 21.1R3-S5; * 21.2 versions prior to 21.2R3-S5; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S4; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S1; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2. This issue does not affect Juniper Networks Junos OS versions prior to 21.1R1
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-09-19 14:10 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Unaffected: 0 , < 21.1R1 (semver)
    Affected: 21.1 , < 21.1R3-S5 (semver)
    Affected: 21.2 , < 21.2R3-S5 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3-S4 (semver)
    Affected: 22.1 , < 22.1R3-S3 (semver)
    Affected: 22.2 , < 22.2R3-S1 (semver)
    Affected: 22.3 , < 22.3R2-S2, 22.3R3 (semver)
    Affected: 22.4 , < 22.4R2 (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 21.1r1 (semver)
    Affected: 21.1 , < 21.1r3-s5 (semver)
    Affected: 21.2 , < 21.2r3-s5 (semver)
    Affected: 21.3 , < 21.3r3-s5 (semver)
    Affected: 21.4 , < 21.4r3-s4 (semver)
    Affected: 22.1 , < ss.1r3-s3 (semver)
    Affected: 22.2 , < 22.2r3-s1 (semver)
    Affected: 22.3 , < 22.3r2-s2 (semver)
    Affected: 22.4 , < 22.4r2 (semver)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-10-11 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:59:51.578Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA73155"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "21.1r1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.1r3-s5",
                    "status": "affected",
                    "version": "21.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2r3-s5",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3r3-s5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4r3-s4",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "ss.1r3-s3",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r3-s1",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r2-s2",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.4r2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-44191",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-19T14:10:10.810352Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-19T14:14:17.438Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "QFX5000 Series",
                "EX4000 Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "21.1R1",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.1R3-S5",
                  "status": "affected",
                  "version": "21.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S5",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S4",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S3",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3-S1",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R2-S2, 22.3R3",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R2",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "datePublic": "2023-10-11T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eAn Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).\u003c/p\u003e\u003cp\u003eOn all Junos OS QFX5000 Series and EX4000 Series platforms, when a high number of VLANs are configured, a specific DHCP packet will cause PFE hogging which will lead to dropping of socket connections.\u003c/p\u003e\u003cp\u003eThis issue affects:\u003c/p\u003e\u003cp\u003eJuniper Networks Junos OS on QFX5000 Series and EX4000 Series\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003e21.1 versions prior to 21.1R3-S5;\u003c/li\u003e\u003cli\u003e21.2 versions prior to 21.2R3-S5;\u003c/li\u003e\u003cli\u003e21.3 versions prior to 21.3R3-S5;\u003c/li\u003e\u003cli\u003e21.4 versions prior to 21.4R3-S4;\u003c/li\u003e\u003cli\u003e22.1 versions prior to 22.1R3-S3;\u003c/li\u003e\u003cli\u003e22.2 versions prior to 22.2R3-S1;\u003c/li\u003e\u003cli\u003e22.3 versions prior to 22.3R2-S2, 22.3R3;\u003c/li\u003e\u003cli\u003e22.4 versions prior to 22.4R2.\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eThis issue does not affect Juniper Networks Junos OS versions prior to 21.1R1\u003c/p\u003e\n\n"
                }
              ],
              "value": "\nAn Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).\n\nOn all Junos OS QFX5000 Series and EX4000 Series platforms, when a high number of VLANs are configured, a specific DHCP packet will cause PFE hogging which will lead to dropping of socket connections.\n\nThis issue affects:\n\nJuniper Networks Junos OS on QFX5000 Series and EX4000 Series\n\n\n\n  *  21.1 versions prior to 21.1R3-S5;\n  *  21.2 versions prior to 21.2R3-S5;\n  *  21.3 versions prior to 21.3R3-S5;\n  *  21.4 versions prior to 21.4R3-S4;\n  *  22.1 versions prior to 22.1R3-S3;\n  *  22.2 versions prior to 22.2R3-S1;\n  *  22.3 versions prior to 22.3R2-S2, 22.3R3;\n  *  22.4 versions prior to 22.4R2.\n\n\n\n\nThis issue does not affect Juniper Networks Junos OS versions prior to 21.1R1\n\n\n\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-12T23:03:20.746Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.juniper.net/JSA73155"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: Junos OS 21.2R3-S5, 21.3R3-S5, 21.4R3-S4, 22.1R3-S3, 22.2R3-S1, 22.3R2-S2, 22.3R3, 22.4R2, 23.2R1, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 21.2R3-S5, 21.3R3-S5, 21.4R3-S4, 22.1R3-S3, 22.2R3-S1, 22.3R2-S2, 22.3R3, 22.4R2, 23.2R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "advisory": "JSA73155",
            "defect": [
              "1711644"
            ],
            "discovery": "USER"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-10-11T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS: QFX5000 Series and EX4000 Series: Denial of Service (DoS) on a large scale VLAN due to PFE hogging",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThere are no known workarounds for this issue.\u003c/p\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-44191",
        "datePublished": "2023-10-12T23:03:20.746Z",
        "dateReserved": "2023-09-26T19:30:27.953Z",
        "dateUpdated": "2024-09-19T14:14:17.438Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-36843 (GCVE-0-2023-36843)

    Vulnerability from nvd โ€“ Published: 2023-10-12 22:58 โ€“ Updated: 2024-09-18 17:53
    VLAI
    Title
    Junos OS: SRX Series: The PFE will crash on receiving malformed SSL traffic when Sky ATP is enabled
    Summary
    An Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby resulting in a Denial of Service (DoS). Upon receiving malformed SSL traffic, the PFE crashes. A manual restart will be needed to recover the device. This issue only affects devices with Juniper Networks Advanced Threat Prevention (ATP) Cloud enabled with Encrypted Traffic Insights (configured via โ€˜security-metadata-streaming policyโ€™). This issue affects Juniper Networks Junos OS: * All versions prior to 20.4R3-S8, 20.4R3-S9; * 21.1 version 21.1R1 and later versions; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3;
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-09-18 17:43 UTC
    CWE
    • CWE-168 - Improper Handling of Inconsistent Special Elements
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 0 , < 20.4R3-S8 (semver)
    Affected: 21.1R1 , < 21.1* (semver)
    Affected: 21.2 , < 21.2R3-S6 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3-S5 (semver)
    Affected: 22.1 , < 22.1R3-S4 (semver)
    Affected: 22.2 , < 22.2R3-S2 (semver)
    Affected: 22.3 , < 22.3R2-S2, 22.3R3 (semver)
    Affected: 22.4 , < 22.4R2-S1, 22.4R3 (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 20.4r3-s8 (semver)
    Affected: 21.1r1 , < 21.1 (semver)
    Affected: 21.2 , < 21.2r3-s6 (semver)
    Affected: 21.3 , < 21.3r3-s5 (semver)
    Affected: 21.4 , < 21.4r3-s5 (semver)
    Affected: 22.1 , < 22.1r3-s2 (semver)
    Affected: 22.2 , < 22.2r3-s2 (semver)
    Affected: 22.3 , < 22.3r2-s2 (semver)
    Affected: 22.3 , < 22.3r3 (semver)
    Affected: 22.4 , < 22.4r2-s2 (semver)
    Affected: 22.4 , < 22.4r3 (semver)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-10-11 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:01:09.673Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA73174"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4r3-s8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.1",
                    "status": "affected",
                    "version": "21.1r1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2r3-s6",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3r3-s5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4r3-s5",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1r3-s2",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r3-s2",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r2-s2",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r3",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.4r2-s2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.4r3",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-36843",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-18T17:43:08.375533Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-168",
                    "description": "CWE-168 Improper Handling of Inconsistent Special Elements",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T17:53:30.073Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "SRX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.1*",
                  "status": "affected",
                  "version": "21.1R1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S6",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S5",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S4",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3-S2",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R2-S2, 22.3R3",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R2-S1, 22.4R3",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe below command configures security-metadata-streaming:\u003c/p\u003e\u003ctt\u003e[ set services security-metadata-streaming policy ]\u003c/tt\u003e"
                }
              ],
              "value": "The below command configures security-metadata-streaming:\n\n[ set services security-metadata-streaming policy ]"
            }
          ],
          "datePublic": "2023-10-11T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eAn Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby resulting in a Denial of Service (DoS).\u003c/p\u003e\u003cp\u003eUpon receiving malformed SSL traffic, the PFE crashes. A manual restart will be needed to recover the device.\u003c/p\u003e\u003cp\u003eThis issue only affects devices with Juniper Networks Advanced Threat Prevention (ATP) Cloud enabled with Encrypted Traffic Insights (configured via \u2018security-metadata-streaming policy\u2019).\u003c/p\u003e\u003cp\u003eThis issue affects Juniper Networks Junos OS:\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003eAll versions prior to 20.4R3-S8, 20.4R3-S9;\u003c/li\u003e\u003cli\u003e21.1 version 21.1R1 and later versions;\u003c/li\u003e\u003cli\u003e21.2 versions prior to 21.2R3-S6;\u003c/li\u003e\u003cli\u003e21.3 versions prior to 21.3R3-S5;\u003c/li\u003e\u003cli\u003e21.4 versions prior to 21.4R3-S5;\u003c/li\u003e\u003cli\u003e22.1 versions prior to 22.1R3-S4;\u003c/li\u003e\u003cli\u003e22.2 versions prior to 22.2R3-S2;\u003c/li\u003e\u003cli\u003e22.3 versions prior to 22.3R2-S2, 22.3R3;\u003c/li\u003e\u003cli\u003e22.4 versions prior to 22.4R2-S1, 22.4R3;\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e\n\n"
                }
              ],
              "value": "\nAn Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby resulting in a Denial of Service (DoS).\n\nUpon receiving malformed SSL traffic, the PFE crashes. A manual restart will be needed to recover the device.\n\nThis issue only affects devices with Juniper Networks Advanced Threat Prevention (ATP) Cloud enabled with Encrypted Traffic Insights (configured via \u2018security-metadata-streaming policy\u2019).\n\nThis issue affects Juniper Networks Junos OS:\n\n\n\n  *  All versions prior to 20.4R3-S8, 20.4R3-S9;\n  *  21.1 version 21.1R1 and later versions;\n  *  21.2 versions prior to 21.2R3-S6;\n  *  21.3 versions prior to 21.3R3-S5;\n  *  21.4 versions prior to 21.4R3-S5;\n  *  22.1 versions prior to 22.1R3-S4;\n  *  22.2 versions prior to 22.2R3-S2;\n  *  22.3 versions prior to 22.3R2-S2, 22.3R3;\n  *  22.4 versions prior to 22.4R2-S1, 22.4R3;\n\n\n\n\n\n\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-168",
                  "description": " CWE-168: Improper Handling of Inconsistent Special Elements",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-12T22:58:49.192Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.juniper.net/JSA73174"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S2, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3, 23.1R2, 23.2R1, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S2, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3, 23.1R2, 23.2R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "advisory": "JSA73174",
            "defect": [
              "1696110"
            ],
            "discovery": "INTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-10-11T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS: SRX Series: The PFE will crash on receiving malformed SSL traffic when Sky ATP is enabled",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eRemoving the security-metadata-streaming policy from the configuration stops the issue.\u003c/p\u003e"
                }
              ],
              "value": "Removing the security-metadata-streaming policy from the configuration stops the issue.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-36843",
        "datePublished": "2023-10-12T22:58:49.192Z",
        "dateReserved": "2023-06-27T16:17:25.276Z",
        "dateUpdated": "2024-09-18T17:53:30.073Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-36841 (GCVE-0-2023-36841)

    Vulnerability from nvd โ€“ Published: 2023-10-12 22:58 โ€“ Updated: 2024-09-18 18:01
    VLAI
    Title
    Junos OS: MX Series: Receipt of malformed TCP traffic will cause a Denial of Service
    Summary
    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS). An attacker who sends malformed TCP traffic via an interface configured with PPPoE, causes an infinite loop on the respective PFE. This results in consuming all resources and a manual restart is needed to recover. This issue affects interfaces with PPPoE configured and tcp-mss enabled. This issue affects Juniper Networks Junos OS * All versions prior to 20.4R3-S7; * 21.1 version 21.1R1 and later versions; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S3; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3; * 22.3 versions prior to 22.3R2-S2; * 22.4 versions prior to 22.4R2;
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-09-18 17:54 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 0 , < 20.4R3-S7 (semver)
    Affected: 21.1R1 , < 21.1* (semver)
    Affected: 21.2 , < 21.2R3-S6 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3-S3 (semver)
    Affected: 22.1 , < 22.1R3-S4 (semver)
    Affected: 22.2 , < 22.2R3 (semver)
    Affected: 22.3 , < 22.3R2-S2, 22.3R3 (semver)
    Affected: 22.4 , < 22.4R2 (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 20.4r3-s7 (semver)
    Affected: 21.1r1 , < 21.1 (semver)
    Affected: 21.2 , < 21.2r3-s6 (semver)
    Affected: 21.3 , < 21.3r3-s5 (semver)
    Affected: 21.4 , < 21.4r3-s3 (semver)
    Affected: 22.1 , < 22.1r3-s4 (semver)
    Affected: 22.2 , < 22.2r3 (semver)
    Affected: 22.3 , < 22.3r2-s2 (semver)
    Affected: 22.3 , < 22.3r3 (semver)
    Affected: 22.4 , < 22.4r2 (semver)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-10-11 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:01:09.926Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA73172"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4r3-s7",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.1",
                    "status": "affected",
                    "version": "21.1r1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2r3-s6",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3r3-s5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4r3-s3",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1r3-s4",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r2-s2",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r3",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.4r2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-36841",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-18T17:54:47.892619Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T18:01:47.921Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "MX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.1*",
                  "status": "affected",
                  "version": "21.1R1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S6",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S3",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S4",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R2-S2, 22.3R3",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R2",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003ePPPoE can be configured with the following commands:\u003c/p\u003e \u003ctt\u003e[ edit interfaces interface-name ]\u003cbr\u003e\u003c/tt\u003e\u003ctt\u003e [ encapsulation ppp-over-ether; ]\u003c/tt\u003e\u003cp\u003etcp-mss can be enabled with the following command:\u003c/p\u003e \u003ctt\u003e[ tcp-mss mss-value; ]\u003c/tt\u003e"
                }
              ],
              "value": "PPPoE can be configured with the following commands:\n\n [ edit interfaces interface-name ]\n [ encapsulation ppp-over-ether; ]tcp-mss can be enabled with the following command:\n\n [ tcp-mss mss-value; ]"
            }
          ],
          "datePublic": "2023-10-11T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eAn Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS).\u003c/p\u003e\u003cp\u003eAn attacker who sends malformed TCP traffic via an interface configured with PPPoE, causes an infinite loop on the respective PFE. This results in consuming all resources and a manual restart is needed to recover.\u003c/p\u003e\u003cp\u003eThis issue affects interfaces with PPPoE configured and tcp-mss enabled.\u003c/p\u003e\u003cp\u003eThis issue affects Juniper Networks Junos OS\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003eAll versions prior to 20.4R3-S7;\u003c/li\u003e\u003cli\u003e21.1 version 21.1R1 and later versions;\u003c/li\u003e\u003cli\u003e21.2 versions prior to 21.2R3-S6;\u003c/li\u003e\u003cli\u003e21.3 versions prior to 21.3R3-S5;\u003c/li\u003e\u003cli\u003e21.4 versions prior to 21.4R3-S3;\u003c/li\u003e\u003cli\u003e22.1 versions prior to 22.1R3-S4;\u003c/li\u003e\u003cli\u003e22.2 versions prior to 22.2R3;\u003c/li\u003e\u003cli\u003e22.3 versions prior to 22.3R2-S2;\u003c/li\u003e\u003cli\u003e22.4 versions prior to 22.4R2;\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e\n\n"
                }
              ],
              "value": "\nAn Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS).\n\nAn attacker who sends malformed TCP traffic via an interface configured with PPPoE, causes an infinite loop on the respective PFE. This results in consuming all resources and a manual restart is needed to recover.\n\nThis issue affects interfaces with PPPoE configured and tcp-mss enabled.\n\nThis issue affects Juniper Networks Junos OS\n\n\n\n  *  All versions prior to 20.4R3-S7;\n  *  21.1 version 21.1R1 and later versions;\n  *  21.2 versions prior to 21.2R3-S6;\n  *  21.3 versions prior to 21.3R3-S5;\n  *  21.4 versions prior to 21.4R3-S3;\n  *  22.1 versions prior to 22.1R3-S4;\n  *  22.2 versions prior to 22.2R3;\n  *  22.3 versions prior to 22.3R2-S2;\n  *  22.4 versions prior to 22.4R2;\n\n\n\n\n\n\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": " CWE-400: Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-12T22:58:14.922Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.juniper.net/JSA73172"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S7, 21.2R3-S6, 21.4R3-S3, 22.1R3-S4, 22.2R3, 22.3R2-S2, 22.3R3, 22.4R2, 23.2R1, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S7, 21.2R3-S6, 21.4R3-S3, 22.1R3-S4, 22.2R3, 22.3R2-S2, 22.3R3, 22.4R2, 23.2R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "advisory": "JSA73172",
            "defect": [
              "1707742"
            ],
            "discovery": "USER"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-10-11T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS: MX Series: Receipt of malformed TCP traffic will cause a Denial of Service",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThere are no known workarounds for this issue.\u003c/p\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-36841",
        "datePublished": "2023-10-12T22:58:14.922Z",
        "dateReserved": "2023-06-27T16:17:25.276Z",
        "dateUpdated": "2024-09-18T18:01:47.921Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-4481 (GCVE-0-2023-4481)

    Vulnerability from nvd โ€“ Published: 2023-08-31 23:46 โ€“ Updated: 2024-10-02 15:09
    VLAI
    Title
    Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
    Summary
    An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When certain specific crafted BGP UPDATE messages are received over an established BGP session, one BGP session may be torn down with an UPDATE message error, or the issue may propagate beyond the local system which will remain non-impacted, but may affect one or more remote systems. This issue is exploitable remotely as the crafted UPDATE message can propagate through unaffected systems and intermediate BGP speakers. Continuous receipt of the crafted BGP UPDATE messages will create a sustained Denial of Service (DoS) condition for impacted devices. This issue affects eBGP and iBGP, in both IPv4 and IPv6 implementations. This issue requires a remote attacker to have at least one established BGP session. Improper Input Validation, Denial of Service vulnerability in Juniper Networks, Inc. Junos OS (BGP, rpd modules), Juniper Networks, Inc. Junos OS Evolved (BGP, rpd modules) allows Fuzzing.This issue affectsย  Junos OS:ย  * All versions before 20.4R3-S10, * from 21.1R1 through 21.*, * from 21.2 before 21.2R3-S5, * from 21.3 before 21.3R3-S5, * from 21.4 before 21.4R3-S7 (unaffected from 21.4R3-S5, affected from 21.4R3-S6) * from 22.1 before 22.1R3-S4, * from 22.2 before 22.2R3-S3, * from 22.3 before 22.3R3-S1, * from 22.4 before 22.4R3, * from 23.2 before 23.2R2. Junos OS Evolved: * All versions before 20.4R3-S10-EVO, * from 21.2-EVO before 21.2R3-S7-EVO, * from 21.3-EVO before 21.3R3-S5-EVO, * from 21.4-EVO before 21.4R3-S5-EVO, * from 22.1-EVO before 22.1R3-S4-EVO, * from 22.2-EVO before 22.2R3-S3-EVO, * from 22.3-EVO before 22.3R3-S1-EVO, * from 22.4-EVO before 22.4R3-EVO, * from 23.2-EVO before 23.2R2-EVO.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-10-02 14:52 UTC
    CWE
    • CWE-20 - Improper Input Validation
    • Denial of Service
    References
    Impacted products
    Vendor Product Version
    Juniper Networks, Inc. Junos OS Affected: 0 , < 20.4R3-S10 (semver)
    Affected: 21.2 , < 21.2R3-S5 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3-S7 (semver)
    Affected: 22.1 , < 22.1R3-S4 (semver)
    Affected: 22.2 , < 22.2R3-S3 (se)
    Affected: 22.3 , < 22.3R3-S1 (semver)
    Affected: 22.4 , < 22.4R3 (semver)
    Affected: 23.2 , < 23.2R2 (semver)
    Affected: 21.1R1 , โ‰ค 21.* (semver)
    Create a notification for this product.
    Juniper Networks, Inc. Junos OS Evolved Affected: 0 , < 20.4R3-S10-EVO (semver)
    Affected: 21.2-EVO , < 21.2R3-S7-EVO (semver)
    Affected: 21.3-EVO , < 21.3R3-S5-EVO (semver)
    Affected: 21.4-EVO , < 21.4R3-S5-EVO (semver)
    Affected: 22.1-EVO , < 22.1R3-S4-EVO (semver)
    Affected: 22.2-EVO , < 22.2R3-S3-EVO (semver)
    Affected: 22.3-EVO , < 22.3R3-S1-EVO (semver)
    Affected: 22.4-EVO , < 22.4R3-EVO (semver)
    Affected: 23.2-EVO , < 23.2R2-EVO (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 20.4R3-S10 (semver)
    Affected: 21.2 , < 21.2R3-S5 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3-S7 (semver)
    Affected: 22.1 , < 22.1R3-S4 (semver)
    Affected: 22.2 , < 22.2R3-S3 (semver)
    Affected: 22.3 , < 22.3R3-S1 (semver)
    Affected: 22.4 , < 22.4R3 (semver)
    Affected: 23.2 , < 23.2R2 (semver)
    Affected: 21.1R1 , < 21.* (semver)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    juniper_networks junos_os_evolved Affected: 0 , < 20.4R3-S10-EVO (semver)
    Affected: 21.2-EVO , < 21.2R3-S7-EVO (semver)
    Affected: 21.3-EVO , < 21.3R3-S5-EVO (semver)
    Affected: 21.4-EVO , < 21.4R3-S5-EVO (semver)
    Affected: 22.1-EVO , < 22.1R3-S4-EVO (custom)
    Affected: 22.2-EVO , < 22.2R3-S3-EVO (semver)
    Affected: 22.3-EVO , < 22.3R3-S1-EVO (semver)
    Affected: 22.4-EVO , < 22.4R3-EVO (semver)
    Affected: 23.2-EVO , < 23.2R2-EVO (semver)
        cpe:2.3:a:juniper_networks:junos_os_evolved:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-08-29 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:31:06.348Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://kb.juniper.net/JSA72510"
              },
              {
                "tags": [
                  "technical-description",
                  "x_transferred"
                ],
                "url": "https://www.rfc-editor.org/rfc/rfc7606"
              },
              {
                "tags": [
                  "technical-description",
                  "x_transferred"
                ],
                "url": "https://www.rfc-editor.org/rfc/rfc4271"
              },
              {
                "tags": [
                  "technical-description",
                  "x_transferred"
                ],
                "url": "https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4R3-S10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2R3-S5",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3R3-S5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4R3-S7",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1R3-S4",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2R3-S3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3R3-S1",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.4R3",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "23.2R2",
                    "status": "affected",
                    "version": "23.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.*",
                    "status": "affected",
                    "version": "21.1R1",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:juniper_networks:junos_os_evolved:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os_evolved",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4R3-S10-EVO",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2R3-S7-EVO",
                    "status": "affected",
                    "version": "21.2-EVO",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3R3-S5-EVO",
                    "status": "affected",
                    "version": "21.3-EVO",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4R3-S5-EVO",
                    "status": "affected",
                    "version": "21.4-EVO",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1R3-S4-EVO",
                    "status": "affected",
                    "version": "22.1-EVO",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.2R3-S3-EVO",
                    "status": "affected",
                    "version": "22.2-EVO",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3R3-S1-EVO",
                    "status": "affected",
                    "version": "22.3-EVO",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.4R3-EVO",
                    "status": "affected",
                    "version": "22.4-EVO",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "23.2R2-EVO",
                    "status": "affected",
                    "version": "23.2-EVO",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-4481",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-02T14:52:11.830739Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-02T15:09:38.010Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "BGP",
                "rpd"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks, Inc.",
              "versions": [
                {
                  "lessThan": "20.4R3-S10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S5",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "changes": [
                    {
                      "at": "21.4R3-S5",
                      "status": "unaffected"
                    },
                    {
                      "at": "21.4R3-S6",
                      "status": "affected"
                    }
                  ],
                  "lessThan": "21.4R3-S7",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S4",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3-S3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "se"
                },
                {
                  "lessThan": "22.3R3-S1",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R3",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "23.2R2",
                  "status": "affected",
                  "version": "23.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "21.*",
                  "status": "affected",
                  "version": "21.1R1",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "modules": [
                "BGP",
                "rpd"
              ],
              "product": "Junos OS Evolved",
              "vendor": "Juniper Networks, Inc.",
              "versions": [
                {
                  "lessThan": "20.4R3-S10-EVO",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S7-EVO",
                  "status": "affected",
                  "version": "21.2-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5-EVO",
                  "status": "affected",
                  "version": "21.3-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S5-EVO",
                  "status": "affected",
                  "version": "21.4-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S4-EVO",
                  "status": "affected",
                  "version": "22.1-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3-S3-EVO",
                  "status": "affected",
                  "version": "22.2-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R3-S1-EVO",
                  "status": "affected",
                  "version": "22.3-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R3-EVO",
                  "status": "affected",
                  "version": "22.4-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "23.2R2-EVO",
                  "status": "affected",
                  "version": "23.2-EVO",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The following minimal configuration is required:\u003cbr\u003e\u003cbr\u003e\u0026nbsp; [protocols bgp]"
                }
              ],
              "value": "The following minimal configuration is required:\n\n\u00a0 [protocols bgp]"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Ben Cartwright-Cox / bgp.tools"
            }
          ],
          "datePublic": "2023-08-29T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAn Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).\u003c/span\u003e\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eWhen certain specific crafted BGP UPDATE messages are received over an established BGP session, one BGP session may be torn down with an UPDATE message error, or the issue may propagate beyond the local system which will remain non-impacted, but may affect one or more remote systems. This issue is exploitable remotely as the crafted UPDATE message can propagate through unaffected systems and intermediate BGP speakers.\u003c/span\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eContinuous receipt of the crafted BGP UPDATE messages will create a sustained Denial of Service (DoS) condition for impacted devices.\u003c/span\u003e\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eThis issue affects eBGP and iBGP, in both IPv4 and IPv6 implementations.  This issue requires a remote attacker to have at least one established BGP session.\u003c/span\u003e\u003cbr\u003e Improper Input Validation, Denial of Service vulnerability in Juniper Networks, Inc. Junos OS (BGP, rpd modules), Juniper Networks, Inc. Junos OS Evolved (BGP, rpd modules) allows Fuzzing.\u003cp\u003eThis issue affects\u0026nbsp;\u003c/p\u003e\u003cp\u003eJunos OS:\u0026nbsp;\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003eAll versions before 20.4R3-S10,\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003efrom 21.1R1 through 21.*,\u003c/span\u003e\u003c/li\u003e\u003cli\u003efrom 21.2 before 21.2R3-S5,\u003c/li\u003e\u003cli\u003efrom 21.3 before 21.3R3-S5,\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003efrom 21.4 before 21.4R3-S7 (unaffected from 21.4R3-S5, affected from 21.4R3-S6)\u003c/span\u003e\u003c/li\u003e\u003cli\u003efrom 22.1 before 22.1R3-S4,\u003c/li\u003e\u003cli\u003efrom 22.2 before 22.2R3-S3,\u003c/li\u003e\u003cli\u003efrom 22.3 before 22.3R3-S1,\u003c/li\u003e\u003cli\u003efrom 22.4 before 22.4R3,\u003c/li\u003e\u003cli\u003efrom 23.2 before 23.2R2.\u003c/li\u003e\u003c/ul\u003e\u003cspan style=\"background-color: var(--wht);\"\u003eJunos OS Evolved:\u003c/span\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003eAll versions before 20.4R3-S10-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 21.2-EVO before 21.2R3-S7-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 21.3-EVO before 21.3R3-S5-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 21.4-EVO before 21.4R3-S5-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 22.1-EVO before 22.1R3-S4-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 22.2-EVO before 22.2R3-S3-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 22.3-EVO before 22.3R3-S1-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 22.4-EVO before 22.4R3-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 23.2-EVO before 23.2R2-EVO.\u003c/span\u003e\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).\n\nWhen certain specific crafted BGP UPDATE messages are received over an established BGP session, one BGP session may be torn down with an UPDATE message error, or the issue may propagate beyond the local system which will remain non-impacted, but may affect one or more remote systems. This issue is exploitable remotely as the crafted UPDATE message can propagate through unaffected systems and intermediate BGP speakers.\nContinuous receipt of the crafted BGP UPDATE messages will create a sustained Denial of Service (DoS) condition for impacted devices.\n\nThis issue affects eBGP and iBGP, in both IPv4 and IPv6 implementations.  This issue requires a remote attacker to have at least one established BGP session.\n Improper Input Validation, Denial of Service vulnerability in Juniper Networks, Inc. Junos OS (BGP, rpd modules), Juniper Networks, Inc. Junos OS Evolved (BGP, rpd modules) allows Fuzzing.This issue affects\u00a0\n\nJunos OS:\u00a0\n\n\n\n  *  All versions before 20.4R3-S10,\n  *  from 21.1R1 through 21.*,\n  *  from 21.2 before 21.2R3-S5,\n  *  from 21.3 before 21.3R3-S5,\n  *  from 21.4 before 21.4R3-S7 (unaffected from 21.4R3-S5, affected from 21.4R3-S6)\n  *  from 22.1 before 22.1R3-S4,\n  *  from 22.2 before 22.2R3-S3,\n  *  from 22.3 before 22.3R3-S1,\n  *  from 22.4 before 22.4R3,\n  *  from 23.2 before 23.2R2.\n\n\nJunos OS Evolved:\n\n\n\n  *  All versions before 20.4R3-S10-EVO,\n  *  from 21.2-EVO before 21.2R3-S7-EVO,\n  *  from 21.3-EVO before 21.3R3-S5-EVO,\n  *  from 21.4-EVO before 21.4R3-S5-EVO,\n  *  from 22.1-EVO before 22.1R3-S4-EVO,\n  *  from 22.2-EVO before 22.2R3-S3-EVO,\n  *  from 22.3-EVO before 22.3R3-S1-EVO,\n  *  from 22.4-EVO before 22.4R3-EVO,\n  *  from 23.2-EVO before 23.2R2-EVO."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-28",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-28 Fuzzing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-27T17:47:11.855Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://kb.juniper.net/JSA72510"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://www.rfc-editor.org/rfc/rfc7606"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://www.rfc-editor.org/rfc/rfc4271"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.html"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue:\u003cbr\u003e\u003c/p\u003e\u003cp\u003eJunos OS: \u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e20.4R3-S10,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.2R3-S7,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.3R3-S5,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.4R3-S5 or \u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.4R3-S7\u003c/span\u003e,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.1R3-S4,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.2R3-S3,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.3R3-S1,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.4R3,\u003c/span\u003e\u0026nbsp;23.2R2, 23.3R2, 23.4R1, and all subsequent releases\u003cbr\u003e\u003c/p\u003e\u003cp\u003eNote: except for Junos OS 21.4R3-S6 which is affected and unfixed.\u003cbr\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eJunos OS Evolved: 20.4R3-S10-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.2R3-S7-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.3R3-S5-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.4R3-S5-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.1R3-S4-EVO,\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;22.2R3-S3-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.3R3-S1-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.4R3-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e23.2R2-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e23.4R1-EVO,\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"background-color: var(--wht);\"\u003e\u0026nbsp;and all subsequent releases.\u003c/span\u003e\u003c/p\u003e\u003cbr\u003eIt is important that customers implement the workaround in addition to taking any updated software as these crafted UPDATE messages may be propagated to other devices even if non-impacted locally, thereby protecting the network by stopping the propagation of these crafted UPDATE messages.\u003cbr\u003eThe workaround is to configure BGP error tolerance by way of:\u003cbr\u003e\u003cbr\u003e\u0026nbsp; [ protocols bgp bgp-error-tolerance ... ]\u003cbr\u003e\u003cbr\u003eAdditional details can be found at \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.html\"\u003ehttps://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.h...\u003c/a\u003e\u003cbr\u003e\u003cbr\u003eJuniper considers configuring this option to be a Best Common Practice (BCP) as it not only prevents this issue from happening, but protects against similar issues as well.\u003cp\u003e\u003c/p\u003e\u003cp\u003eThis issue is being tracked as PR \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://prsearch.juniper.net/problemreport/PR1709837\"\u003e1709837\u003c/a\u003e\u0026nbsp;which is visible on the Customer Support website.\u003c/p\u003e\u003cp\u003eNote: Juniper SIRT\u0027s \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://kb.juniper.net/KB16765\"\u003epolicy\u003c/a\u003e\u0026nbsp;is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).\u003c/p\u003e\u003cbr\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue:\n\n\nJunos OS: 20.4R3-S10,\u00a021.2R3-S7,\u00a021.3R3-S5,\u00a021.4R3-S5 or 21.4R3-S7,\u00a022.1R3-S4,\u00a022.2R3-S3,\u00a022.3R3-S1,\u00a022.4R3,\u00a023.2R2, 23.3R2, 23.4R1, and all subsequent releases\n\n\nNote: except for Junos OS 21.4R3-S6 which is affected and unfixed.\n\n\n\n\nJunos OS Evolved: 20.4R3-S10-EVO,\u00a021.2R3-S7-EVO,\u00a021.3R3-S5-EVO,\u00a021.4R3-S5-EVO,\u00a022.1R3-S4-EVO,\u00a022.2R3-S3-EVO,\u00a022.3R3-S1-EVO,\u00a022.4R3-EVO,\u00a023.2R2-EVO,\u00a023.4R1-EVO,\u00a0and all subsequent releases.\n\n\nIt is important that customers implement the workaround in addition to taking any updated software as these crafted UPDATE messages may be propagated to other devices even if non-impacted locally, thereby protecting the network by stopping the propagation of these crafted UPDATE messages.\nThe workaround is to configure BGP error tolerance by way of:\n\n\u00a0 [ protocols bgp bgp-error-tolerance ... ]\n\nAdditional details can be found at  https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.h... https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.html \n\nJuniper considers configuring this option to be a Best Common Practice (BCP) as it not only prevents this issue from happening, but protects against similar issues as well.\n\nThis issue is being tracked as PR  1709837 https://prsearch.juniper.net/problemreport/PR1709837 \u00a0which is visible on the Customer Support website.\n\nNote: Juniper SIRT\u0027s  policy https://kb.juniper.net/KB16765 \u00a0is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL)."
            }
          ],
          "source": {
            "advisory": "JSA72510",
            "defect": [
              "1709837"
            ],
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-08-29T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eThe workaround is to configure BGP error tolerance by way of:\u003c/span\u003e\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp; [ protocols bgp bgp-error-tolerance ... ]\u003c/span\u003e\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAdditional details can be found at \u003c/span\u003e\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.html\"\u003ehttps://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.h...\u003c/a\u003e\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eJuniper considers configuring this option to be a Best Common Practice (BCP) as it not only prevents this issue from happening, but protects against similar issues as well.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "The workaround is to configure BGP error tolerance by way of:\n\n\u00a0 [ protocols bgp bgp-error-tolerance ... ]\n\nAdditional details can be found at  https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.h... https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.html \n\nJuniper considers configuring this option to be a Best Common Practice (BCP) as it not only prevents this issue from happening, but protects against similar issues as well."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-4481",
        "datePublished": "2023-08-31T23:46:18.796Z",
        "dateReserved": "2023-08-22T15:37:01.371Z",
        "dateUpdated": "2024-10-02T15:09:38.010Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-36835 (GCVE-0-2023-36835)

    Vulnerability from nvd โ€“ Published: 2023-07-14 17:11 โ€“ Updated: 2024-11-07 14:24
    VLAI
    Title
    Junos OS: QFX10000 Series: All traffic will be dropped after a specific valid IP packet has been received which needs to be routed over a VXLAN tunnel
    Summary
    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX10000 Series allows a network based attacker to cause a Denial of Service (DoS). If a specific valid IP packet is received and that packet needs to be routed over a VXLAN tunnel, this will result in a PFE wedge condition due to which traffic gets impacted. As this is not a crash and restart scenario, this condition will persist until the system is rebooted to recover. This issue affects Juniper Networks Junos OS on QFX10000: 20.3 version 20.3R1 and later versions; 20.4 versions prior to 20.4R3-S5; 21.1 versions prior to 21.1R3-S5; 21.2 versions prior to 21.2R3-S5; 21.3 versions prior to 21.3R3-S4; 21.4 versions prior to 21.4R3-S1; 22.1 versions prior to 22.1R3; 22.2 versions prior to 22.2R2; 22.3 versions prior to 22.3R1-S2, 22.3R2.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-11-07 14:18 UTC
    CWE
    • CWE-754 - Improper Check for Unusual or Exceptional Conditions
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 20.3 , < 20.3* (custom)
    Affected: 20.4 , < 20.4R3-S5 (custom)
    Affected: 21.1 , < 21.1R3-S5 (custom)
    Affected: 21.2 , < 21.2R3-S5 (custom)
    Affected: 21.3 , < 21.3R3-S4 (custom)
    Affected: 21.4 , < 21.4R3-S1 (custom)
    Affected: 22.1 , < 22.1R3 (custom)
    Affected: 22.2 , < 22.2R2 (custom)
    Affected: 22.3 , < 22.3R1-S2, 22.3R2 (custom)
    Create a notification for this product.
    juniper_networks junos_os Affected: 20.3 , < 20.3* (custom)
    Affected: 20.4 , < 20.4R3-S5 (custom)
    Affected: 21.1 , < 21.1R3-S5 (custom)
    Affected: 21.2 , < 21.2R3-S5 (custom)
    Affected: 21.3 , < 21.3R3-S4 (custom)
    Affected: 21.4 , < 21.4R3-S1 (custom)
    Affected: 22.1 , < 22.1R3 (custom)
    Affected: 22.2 , < 22.2R2 (custom)
    Affected: 22.3 , < 22.3R1-S2 (custom)
    Affected: 22.3 , < 22.3R2 (custom)
        cpe:2.3:a:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-07-12 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:01:09.846Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA71642"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.3*",
                    "status": "affected",
                    "version": "20.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.4R3-S5",
                    "status": "affected",
                    "version": "20.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.1R3-S5",
                    "status": "affected",
                    "version": "21.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2R3-S5",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.3R3-S4",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.4R3-S1",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1R3",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.2R2",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R1-S2",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R2",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-36835",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-07T14:18:56.731957Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-07T14:24:52.880Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "QFX10000 Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "20.3R1",
                      "status": "affected"
                    }
                  ],
                  "lessThan": "20.3*",
                  "status": "affected",
                  "version": "20.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "20.4R3-S5",
                  "status": "affected",
                  "version": "20.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.1R3-S5",
                  "status": "affected",
                  "version": "21.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.2R3-S5",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.3R3-S4",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.4R3-S1",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.1R3",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.2R2",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.3R1-S2, 22.3R2",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "To be exposed to this issue the QFX device needs be configured for VXLAN with either of the following statements:\u003cbr\u003e\u003cbr\u003e\u003ctt\u003e\u0026nbsp; [ vlans \u0026lt;vlan\u0026gt; vxlan ]\u003cbr\u003e\u003cbr\u003e\u0026nbsp; [ routing-instances \u0026lt;routing-instance\u0026gt; vxlan ]\u003c/tt\u003e"
                }
              ],
              "value": "To be exposed to this issue the QFX device needs be configured for VXLAN with either of the following statements:\n\n\u00a0 [ vlans \u003cvlan\u003e vxlan ]\n\n\u00a0 [ routing-instances \u003crouting-instance\u003e vxlan ]"
            }
          ],
          "datePublic": "2023-07-12T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX10000 Series allows a network based attacker to cause a Denial of Service (DoS).\u003cbr\u003e\u003cbr\u003eIf a specific valid IP packet is received and that packet needs to be routed over a VXLAN tunnel, this will result in a PFE wedge condition due to which traffic gets impacted. As this is not a crash and restart scenario, this condition will persist until the system is rebooted to recover.\u003cbr\u003e\u003cbr\u003eThis issue affects Juniper Networks Junos OS on QFX10000:\u003cbr\u003e20.3 version 20.3R1 and later versions;\u003cbr\u003e20.4 versions prior to 20.4R3-S5;\u003cbr\u003e21.1 versions prior to 21.1R3-S5;\u003cbr\u003e21.2 versions prior to 21.2R3-S5;\u003cbr\u003e21.3 versions prior to 21.3R3-S4;\u003cbr\u003e21.4 versions prior to 21.4R3-S1;\u003cbr\u003e22.1 versions prior to 22.1R3;\u003cbr\u003e22.2 versions prior to 22.2R2;\u003cbr\u003e22.3 versions prior to 22.3R1-S2, 22.3R2.\u003cbr\u003e"
                }
              ],
              "value": "An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX10000 Series allows a network based attacker to cause a Denial of Service (DoS).\n\nIf a specific valid IP packet is received and that packet needs to be routed over a VXLAN tunnel, this will result in a PFE wedge condition due to which traffic gets impacted. As this is not a crash and restart scenario, this condition will persist until the system is rebooted to recover.\n\nThis issue affects Juniper Networks Junos OS on QFX10000:\n20.3 version 20.3R1 and later versions;\n20.4 versions prior to 20.4R3-S5;\n21.1 versions prior to 21.1R3-S5;\n21.2 versions prior to 21.2R3-S5;\n21.3 versions prior to 21.3R3-S4;\n21.4 versions prior to 21.4R3-S1;\n22.1 versions prior to 22.1R3;\n22.2 versions prior to 22.2R2;\n22.3 versions prior to 22.3R1-S2, 22.3R2.\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003cbr\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-754",
                  "description": "CWE-754 Improper Check for Unusual or Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-07-14T17:11:26.454Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "url": "https://supportportal.juniper.net/JSA71642"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S5, 21.1R3-S5, 21.2R3-S5, 21.3R3-S4, 21.4R3-S1, 22.1R3, 22.2R2, 22.3R1-S2, 22.3R2, 22.4R1, and all subsequent releases.\u003cbr\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S5, 21.1R3-S5, 21.2R3-S5, 21.3R3-S4, 21.4R3-S1, 22.1R3, 22.2R2, 22.3R1-S2, 22.3R2, 22.4R1, and all subsequent releases.\n"
            }
          ],
          "source": {
            "advisory": "JSA71642",
            "defect": [
              "1678992"
            ],
            "discovery": "USER"
          },
          "title": "Junos OS: QFX10000 Series: All traffic will be dropped after a specific valid IP packet has been received which needs to be routed over a VXLAN tunnel",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "There are no known workarounds for this issue.\u003cbr\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-36835",
        "datePublished": "2023-07-14T17:11:26.454Z",
        "dateReserved": "2023-06-27T16:17:25.276Z",
        "dateUpdated": "2024-11-07T14:24:52.880Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-28985 (GCVE-0-2023-28985)

    Vulnerability from nvd โ€“ Published: 2023-07-14 16:34 โ€“ Updated: 2024-11-07 14:28
    VLAI
    Title
    SRX Series and MX Series: An FPC core is observed when IDP is enabled on the device and a specific malformed SSL packet is received
    Summary
    An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and MX Series allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Continued receipt of this specific packet will cause a sustained Denial of Service condition. On all SRX Series and MX Series platforms, where IDP is enabled and a specific malformed SSL packet is received, the SSL detector crashes leading to an FPC core. This issue affects Juniper Networks SRX Series and MX Series prior to SigPack 3598. In order to identify the current SigPack version, following command can be used: user@junos# show security idp security-package-version
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-11-07 14:25 UTC
    CWE
    • CWE-1286 - Improper Validation of Syntactic Correctness of Input
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: unspecified , < SigPack 3598 (custom)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < SigPack 3598 (custom)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-07-12 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T13:51:39.183Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA71662"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "SigPack 3598",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-28985",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-07T14:25:45.770994Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-07T14:28:11.378Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "SRX Series",
                "MX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "SigPack 3598",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "For this issue to occur, IDP policy has to be enabled on the SRX and MX Series devices to inspect the HTTPS traffic.\u003cbr\u003e\u003cbr\u003e\u003ctt\u003e[ security idp active-policy policy-name ]\u003cbr\u003e[ security idp idp-policy policy-name rulebase-ips rule rule-name ]\u003c/tt\u003e"
                }
              ],
              "value": "For this issue to occur, IDP policy has to be enabled on the SRX and MX Series devices to inspect the HTTPS traffic.\n\n[ security idp active-policy policy-name ]\n[ security idp idp-policy policy-name rulebase-ips rule rule-name ]"
            }
          ],
          "datePublic": "2023-07-12T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and MX Series allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Continued receipt of this specific packet will cause a sustained Denial of Service condition.\u003cbr\u003e\u003cbr\u003eOn all SRX Series and MX Series platforms, where IDP is enabled and a specific malformed SSL packet is received, the SSL detector crashes leading to an FPC core.\u003cbr\u003e\u003cbr\u003eThis issue affects Juniper Networks SRX Series and MX Series prior to SigPack 3598.\u003cbr\u003e\u003cbr\u003eIn order to identify the current SigPack version, following command can be used:\u003cbr\u003e\u003cbr\u003e\u003ctt\u003euser@junos# show security idp security-package-version\u003c/tt\u003e"
                }
              ],
              "value": "An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and MX Series allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Continued receipt of this specific packet will cause a sustained Denial of Service condition.\n\nOn all SRX Series and MX Series platforms, where IDP is enabled and a specific malformed SSL packet is received, the SSL detector crashes leading to an FPC core.\n\nThis issue affects Juniper Networks SRX Series and MX Series prior to SigPack 3598.\n\nIn order to identify the current SigPack version, following command can be used:\n\nuser@junos# show security idp security-package-version"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003cbr\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1286",
                  "description": "CWE-1286 Improper Validation of Syntactic Correctness of Input",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-07-14T16:34:24.993Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "url": "https://supportportal.juniper.net/JSA71662"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The following software releases have been updated to resolve this specific issue: SigPack 3598, and all subsequent releases.\u003cbr\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: SigPack 3598, and all subsequent releases.\n"
            }
          ],
          "source": {
            "advisory": "JSA71662",
            "defect": [
              "1655071"
            ],
            "discovery": "USER"
          },
          "title": "SRX Series and MX Series: An FPC core is observed when IDP is enabled on the device and a specific malformed SSL packet is received",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "There are no known workarounds for this issue.\u003cbr\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-28985",
        "datePublished": "2023-07-14T16:34:24.993Z",
        "dateReserved": "2023-03-29T08:44:10.679Z",
        "dateUpdated": "2024-11-07T14:28:11.378Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-36832 (GCVE-0-2023-36832)

    Vulnerability from nvd โ€“ Published: 2023-07-14 15:56 โ€“ Updated: 2024-11-07 14:37
    VLAI
    Title
    Junos OS: MX Series: PFE crash upon receipt of specific packet destined to an AMS interface
    Summary
    An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) interface on the device, causing the packet forwarding engine (PFE) to crash, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue is only triggered by packets destined to a local-interface via a service-interface (AMS). AMS is only supported on the MS-MPC, MS-MIC, and MX-SPC3 cards. This issue is not experienced on other types of interfaces or configurations. Additionally, transit traffic does not trigger this issue. This issue affects Juniper Networks Junos OS on MX Series: All versions prior to 19.1R3-S10; 19.2 versions prior to 19.2R3-S7; 19.3 versions prior to 19.3R3-S8; 19.4 versions prior to 19.4R3-S12; 20.2 versions prior to 20.2R3-S8; 20.4 versions prior to 20.4R3-S7; 21.1 versions prior to 21.1R3-S5; 21.2 versions prior to 21.2R3-S5; 21.3 versions prior to 21.3R3-S4; 21.4 versions prior to 21.4R3-S3; 22.1 versions prior to 22.1R3-S2; 22.2 versions prior to 22.2R3; 22.3 versions prior to 22.3R2-S1, 22.3R3; 22.4 versions prior to 22.4R1-S2, 22.4R2.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-11-07 14:29 UTC
    CWE
    • CWE-755 - Improper Handling of Exceptional Conditions
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: unspecified , < 19.1R3-S10 (custom)
    Affected: 19.2 , < 19.2R3-S7 (custom)
    Affected: 19.3 , < 19.3R3-S8 (custom)
    Affected: 19.4 , < 19.4R3-S12 (custom)
    Affected: 20.2 , < 20.2R3-S8 (custom)
    Affected: 20.4 , < 20.4R3-S7 (custom)
    Affected: 21.1 , < 21.1R3-S5 (custom)
    Affected: 21.2 , < 21.2R3-S5 (custom)
    Affected: 21.3 , < 21.3R3-S4 (custom)
    Affected: 21.4 , < 21.4R3-S3 (custom)
    Affected: 22.1 , < 22.1R3-S2 (custom)
    Affected: 22.2 , < 22.2R3 (custom)
    Affected: 22.3 , < 22.3R2-S1, 22.3R3 (custom)
    Affected: 22.4 , < 22.4R1-S2, 22.4R2 (custom)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 19.1R3-S10 (custom)
    Affected: 19.2 , < 19.2R3-S7 (custom)
    Affected: 19.3 , < 19.3R3-S8 (custom)
    Affected: 19.4 , < 19.4R3-S12 (custom)
    Affected: 20.2 , < 20.2R3-S8 (custom)
    Affected: 20.4 , < 20.4R3-S7 (custom)
    Affected: 21.1 , < 21.1R3-S5 (custom)
    Affected: 21.2 , < 21.2R3-S5 (custom)
    Affected: 21.3 , < 22.3R2-S1 (custom)
    Affected: 21.4 , < 21.4R3-S3 (custom)
    Affected: 22.1 , < 22.1R3-S2 (custom)
    Affected: 22.2 , < 22.2R3 (custom)
    Affected: 22.3 , < 22.3R2-S1 (custom)
    Affected: 22.3 , < 22.3R3 (custom)
    Affected: 22.4 , < 22.4R1-S2 (custom)
    Affected: 22.4 , < 22.4R2 (custom)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-07-12 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:01:09.608Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA71639"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "19.1R3-S10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "19.2R3-S7",
                    "status": "affected",
                    "version": "19.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "19.3R3-S8",
                    "status": "affected",
                    "version": "19.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "19.4R3-S12",
                    "status": "affected",
                    "version": "19.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.2R3-S8",
                    "status": "affected",
                    "version": "20.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.4R3-S7",
                    "status": "affected",
                    "version": "20.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.1R3-S5",
                    "status": "affected",
                    "version": "21.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2R3-S5",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R2-S1",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.4R3-S3",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1R3-S2",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.2R3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R2-S1",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R3",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4R1-S2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4R2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-36832",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-07T14:29:02.801765Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-07T14:37:52.265Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "MX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "19.1R3-S10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "19.2R3-S7",
                  "status": "affected",
                  "version": "19.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "19.3R3-S8",
                  "status": "affected",
                  "version": "19.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "19.4R3-S12",
                  "status": "affected",
                  "version": "19.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "20.2R3-S8",
                  "status": "affected",
                  "version": "20.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "20.4R3-S7",
                  "status": "affected",
                  "version": "20.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.1R3-S5",
                  "status": "affected",
                  "version": "21.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.2R3-S5",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.3R3-S4",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.4R3-S3",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.1R3-S2",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.2R3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.3R2-S1, 22.3R3",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.4R1-S2, 22.4R2",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A sample next-hop-service interface configuration is shown below:\u003cbr\u003e\u003cbr\u003e\u003ctt\u003e\u003cb\u003e\u0026nbsp; set services service-set 3 next-hop-service inside-service-interface ams0.1\u003c/b\u003e\u003cbr\u003e\u003cb\u003e\u0026nbsp; set services service-set 3 next-hop-service outside-service-interface ams0.2\u003c/b\u003e\u003cbr\u003e\u0026nbsp; set services nat rule 1 match-direction input\u003cbr\u003e\u0026nbsp; set services nat rule 1 term 1 from source-address 10.10.10.0/24\u003cbr\u003e\u0026nbsp; set services nat rule 1 term 1 then translated source-pool 1\u003cbr\u003e\u003cb\u003e\u0026nbsp; set services nat rule 1 term 1 then translated translation-type napt-44\u003c/b\u003e\u003cbr\u003e\u0026nbsp; set services nat rule 1 term 1 then translated mapping-type endpoint-independent\u003cbr\u003e\u003cbr\u003e\u0026nbsp; set interfaces ams0 load-balancing-options member-interface mams-0/2/0\u003cbr\u003e\u003cbr\u003e\u003cb\u003e\u0026nbsp; set routing-instances 2 routing-options static route 0.0.0.0/0 next-hop ams0.1\u003c/b\u003e\u003cbr\u003e\u0026nbsp; set routing-instances 2 instance-type virtual-router\u003cbr\u003e\u0026nbsp; set routing-instances 2 interface xe-0/0/0.0\u003cbr\u003e\u0026nbsp; set routing-instances 2 interface ams0.1\u003c/tt\u003e\u003cbr\u003e"
                }
              ],
              "value": "A sample next-hop-service interface configuration is shown below:\n\n\u00a0 set services service-set 3 next-hop-service inside-service-interface ams0.1\n\u00a0 set services service-set 3 next-hop-service outside-service-interface ams0.2\n\u00a0 set services nat rule 1 match-direction input\n\u00a0 set services nat rule 1 term 1 from source-address 10.10.10.0/24\n\u00a0 set services nat rule 1 term 1 then translated source-pool 1\n\u00a0 set services nat rule 1 term 1 then translated translation-type napt-44\n\u00a0 set services nat rule 1 term 1 then translated mapping-type endpoint-independent\n\n\u00a0 set interfaces ams0 load-balancing-options member-interface mams-0/2/0\n\n\u00a0 set routing-instances 2 routing-options static route 0.0.0.0/0 next-hop ams0.1\n\u00a0 set routing-instances 2 instance-type virtual-router\n\u00a0 set routing-instances 2 interface xe-0/0/0.0\n\u00a0 set routing-instances 2 interface ams0.1\n"
            }
          ],
          "datePublic": "2023-07-12T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) interface on the device, causing the packet forwarding engine (PFE) to crash, resulting in a Denial of Service (DoS).  Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.\u003cbr\u003e\u003cbr\u003eThis issue is only triggered by packets destined to a local-interface via a service-interface (AMS).  AMS is only supported on the MS-MPC, MS-MIC, and MX-SPC3 cards.  This issue is not experienced on other types of interfaces or configurations.  Additionally, transit traffic does not trigger this issue.\u003cbr\u003e\u003cbr\u003eThis issue affects Juniper Networks Junos OS on MX Series:\u003cbr\u003eAll versions prior to 19.1R3-S10;\u003cbr\u003e19.2 versions prior to 19.2R3-S7;\u003cbr\u003e19.3 versions prior to 19.3R3-S8;\u003cbr\u003e19.4 versions prior to 19.4R3-S12;\u003cbr\u003e20.2 versions prior to 20.2R3-S8;\u003cbr\u003e20.4 versions prior to 20.4R3-S7;\u003cbr\u003e21.1 versions prior to 21.1R3-S5;\u003cbr\u003e21.2 versions prior to 21.2R3-S5;\u003cbr\u003e21.3 versions prior to 21.3R3-S4;\u003cbr\u003e21.4 versions prior to 21.4R3-S3;\u003cbr\u003e22.1 versions prior to 22.1R3-S2;\u003cbr\u003e22.2 versions prior to 22.2R3;\u003cbr\u003e22.3 versions prior to 22.3R2-S1, 22.3R3;\u003cbr\u003e22.4 versions prior to 22.4R1-S2, 22.4R2.\u003cbr\u003e"
                }
              ],
              "value": "An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) interface on the device, causing the packet forwarding engine (PFE) to crash, resulting in a Denial of Service (DoS).  Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.\n\nThis issue is only triggered by packets destined to a local-interface via a service-interface (AMS).  AMS is only supported on the MS-MPC, MS-MIC, and MX-SPC3 cards.  This issue is not experienced on other types of interfaces or configurations.  Additionally, transit traffic does not trigger this issue.\n\nThis issue affects Juniper Networks Junos OS on MX Series:\nAll versions prior to 19.1R3-S10;\n19.2 versions prior to 19.2R3-S7;\n19.3 versions prior to 19.3R3-S8;\n19.4 versions prior to 19.4R3-S12;\n20.2 versions prior to 20.2R3-S8;\n20.4 versions prior to 20.4R3-S7;\n21.1 versions prior to 21.1R3-S5;\n21.2 versions prior to 21.2R3-S5;\n21.3 versions prior to 21.3R3-S4;\n21.4 versions prior to 21.4R3-S3;\n22.1 versions prior to 22.1R3-S2;\n22.2 versions prior to 22.2R3;\n22.3 versions prior to 22.3R2-S1, 22.3R3;\n22.4 versions prior to 22.4R1-S2, 22.4R2.\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003cbr\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-755",
                  "description": "CWE-755 Improper Handling of Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-07-14T15:56:44.005Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "url": "https://supportportal.juniper.net/JSA71639"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The following software releases have been updated to resolve this specific issue: 19.1R3-S10, 19.2R3-S7, 19.3R3-S8, 19.4R3-S12, 20.2R3-S8, 20.4R3-S7, 21.1R3-S5, 21.2R3-S5, 21.3R3-S4, 21.4R3-S3, 22.1R3-S2, 22.2R3, 22.3R2-S1, 22.3R3, 22.4R1-S2, 22.4R2, 23.1R1, and all subsequent releases.\u003cbr\u003e\u003cbr\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: 19.1R3-S10, 19.2R3-S7, 19.3R3-S8, 19.4R3-S12, 20.2R3-S8, 20.4R3-S7, 21.1R3-S5, 21.2R3-S5, 21.3R3-S4, 21.4R3-S3, 22.1R3-S2, 22.2R3, 22.3R2-S1, 22.3R3, 22.4R1-S2, 22.4R2, 23.1R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "defect": [
              "1707140"
            ],
            "discovery": "USER"
          },
          "title": "Junos OS: MX Series: PFE crash upon receipt of specific packet destined to an AMS interface",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Modify the configuration to not have local/host bound ICMP traffic processed by Service Card (MS-MPC/SPC3) or add protect-RE filter to discard ICMP packets.\u003cbr\u003e"
                }
              ],
              "value": "Modify the configuration to not have local/host bound ICMP traffic processed by Service Card (MS-MPC/SPC3) or add protect-RE filter to discard ICMP packets.\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-36832",
        "datePublished": "2023-07-14T15:56:44.005Z",
        "dateReserved": "2023-06-27T16:17:25.275Z",
        "dateUpdated": "2024-11-07T14:37:52.265Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-36831 (GCVE-0-2023-36831)

    Vulnerability from nvd โ€“ Published: 2023-07-14 14:56 โ€“ Updated: 2024-11-07 14:41
    VLAI
    Title
    Junos OS: SRX Series: jbuf memory leak when SSL Proxy and UTM Web-Filtering is applied
    Summary
    An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading to a Denial of Service (DoS) condition. Service restoration is only possible by rebooting the system. The jbuf memory leak only occurs in SSL Proxy and UTM Web-Filtering configurations. Other products, platforms, and configurations are not affected by this vulnerability. This issue affects Juniper Networks Junos OS on SRX Series: 22.2 versions prior to 22.2R3; 22.3 versions prior to 22.3R2-S1, 22.3R3; 22.4 versions prior to 22.4R1-S2, 22.4R2. This issue does not affect Juniper Networks Junos OS versions prior to 22.2R2.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-11-07 14:39 UTC
    CWE
    • CWE-703 - Improper Check or Handling of Exceptional Conditions
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 22.2 , < 22.2R3 (custom)
    Affected: 22.3 , < 22.3R2-S1, 22.3R3 (custom)
    Affected: 22.4 , < 22.4R1-S2, 22.4R2 (custom)
    Unaffected: unspecified , < 22.2R2 (custom)
    Create a notification for this product.
    juniper_networks junos_os Affected: 22.2 , < 22.2R3 (custom)
    Affected: 22.3 , < 22.3R2-S1 (custom)
    Affected: 22.3 , < 22.3R3 (custom)
    Affected: 22.4 , < 22.4R1-S2 (custom)
    Affected: 22.4 , < 22.4R2 (custom)
    Affected: 0 , < 22.2R2 (custom)
        cpe:2.3:a:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-07-12 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:01:09.920Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA71636"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "22.2R3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R2-S1",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R3",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4R1-S2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4R2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.2R2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-36831",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-07T14:39:03.046485Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-07T14:41:49.644Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "SRX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "22.2R3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.3R2-S1, 22.3R3",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.4R1-S2, 22.4R2",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.2R2",
                  "status": "unaffected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The following sample configuration options highlight the features required to be affected by this issue:\u003cbr\u003e\u003ctt\u003e\u0026nbsp; set services ssl proxy profile SSL-PROXY protocol-version tls12-and-lower\u003cbr\u003e\u0026nbsp; set services ssl proxy profile SSL-PROXY trusted-ca all\u003cbr\u003e\u0026nbsp; set services ssl proxy profile SSL-PROXY root-ca ssl-proxy-ecdsa1\u003cbr\u003e\u0026nbsp; set security pki ca-profile SECURITY-CA-GROUP_1 ca-identity SECURITY-CA-GROUP_1\u003cbr\u003e\u003c/tt\u003e...\u003cbr\u003e\u003ctt\u003e\u0026nbsp; set security utm default-configuration web-filtering juniper-enhanced default log-and-permit\u003cbr\u003e\u0026nbsp; set security utm feature-profile web-filtering juniper-enhanced profile 2 category ... action block\u003cbr\u003e\u003c/tt\u003e...\u003cbr\u003e\u003ctt\u003e\u0026nbsp; set security utm utm-policy 1 web-filtering http-profile 2\u003cbr\u003e\u003c/tt\u003e...\u003cbr\u003e\u003ctt\u003e\u0026nbsp; set security policies from-zone private to-zone internet policy 1 then permit application-services ssl-proxy profile-name SSL-PROXY\u003cbr\u003e\u0026nbsp; set security policies from-zone private to-zone internet policy 1 then permit application-services utm-policy 1\u003c/tt\u003e\u003cbr\u003e"
                }
              ],
              "value": "The following sample configuration options highlight the features required to be affected by this issue:\n\u00a0 set services ssl proxy profile SSL-PROXY protocol-version tls12-and-lower\n\u00a0 set services ssl proxy profile SSL-PROXY trusted-ca all\n\u00a0 set services ssl proxy profile SSL-PROXY root-ca ssl-proxy-ecdsa1\n\u00a0 set security pki ca-profile SECURITY-CA-GROUP_1 ca-identity SECURITY-CA-GROUP_1\n...\n\u00a0 set security utm default-configuration web-filtering juniper-enhanced default log-and-permit\n\u00a0 set security utm feature-profile web-filtering juniper-enhanced profile 2 category ... action block\n...\n\u00a0 set security utm utm-policy 1 web-filtering http-profile 2\n...\n\u00a0 set security policies from-zone private to-zone internet policy 1 then permit application-services ssl-proxy profile-name SSL-PROXY\n\u00a0 set security policies from-zone private to-zone internet policy 1 then permit application-services utm-policy 1\n"
            }
          ],
          "datePublic": "2023-07-12T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading to a Denial of Service (DoS) condition.  Service restoration is only possible by rebooting the system.\u003cbr\u003e\u003cbr\u003eThe jbuf memory leak only occurs in SSL Proxy and UTM Web-Filtering configurations.  Other products, platforms, and configurations are not affected by this vulnerability.\u003cbr\u003e\u003cbr\u003eThis issue affects Juniper Networks Junos OS on SRX Series:\u003cbr\u003e22.2 versions prior to 22.2R3;\u003cbr\u003e22.3 versions prior to 22.3R2-S1, 22.3R3;\u003cbr\u003e22.4 versions prior to 22.4R1-S2, 22.4R2.\u003cbr\u003e\u003cbr\u003eThis issue does not affect Juniper Networks Junos OS versions prior to 22.2R2.\u003cbr\u003e"
                }
              ],
              "value": "An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading to a Denial of Service (DoS) condition.  Service restoration is only possible by rebooting the system.\n\nThe jbuf memory leak only occurs in SSL Proxy and UTM Web-Filtering configurations.  Other products, platforms, and configurations are not affected by this vulnerability.\n\nThis issue affects Juniper Networks Junos OS on SRX Series:\n22.2 versions prior to 22.2R3;\n22.3 versions prior to 22.3R2-S1, 22.3R3;\n22.4 versions prior to 22.4R1-S2, 22.4R2.\n\nThis issue does not affect Juniper Networks Junos OS versions prior to 22.2R2.\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003cbr\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-703",
                  "description": "CWE-703 Improper Check or Handling of Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-07-14T14:56:32.306Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "url": "https://supportportal.juniper.net/JSA71636"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The following software releases have been updated to resolve this specific issue: Junos OS 22.2R3, 22.3R2-S1, 22.3R3, 22.4R1-S2, 22.4R2, 23.1R1, and all subsequent releases.\u003cbr\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 22.2R3, 22.3R2-S1, 22.3R3, 22.4R1-S2, 22.4R2, 23.1R1, and all subsequent releases.\n"
            }
          ],
          "source": {
            "defect": [
              "1709031"
            ],
            "discovery": "USER"
          },
          "title": "Junos OS: SRX Series: jbuf memory leak when SSL Proxy and UTM Web-Filtering is applied",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "There are no known workarounds for this issue.\u003cbr\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-36831",
        "datePublished": "2023-07-14T14:56:32.306Z",
        "dateReserved": "2023-06-27T16:17:25.275Z",
        "dateUpdated": "2024-11-07T14:41:49.644Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-21598 (GCVE-0-2024-21598)

    Vulnerability from cvelistv5 โ€“ Published: 2024-04-12 14:54 โ€“ Updated: 2024-08-01 22:27
    VLAI
    Title
    Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash
    Summary
    An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute with a specifically malformed TLV, rpd will crash and restart. This issue affects Juniper Networks Junos OS: * 20.4 versions 20.4R1 and later versions earlier than 20.4R3-S9; * 21.2 versions earlier than 21.2R3-S7; * 21.3 versions earlier than 21.3R3-S5; * 21.4 versions earlier than 21.4R3-S5; * 22.1 versions earlier than 22.1R3-S4; * 22.2 versions earlier than 22.2R3-S3; * 22.3 versions earlier than 22.3R3-S1; * 22.4 versions earlier than 22.4R3; * 23.2 versions earlier than 23.2R1-S2, 23.2R2; Junos OS Evolved: * 20.4-EVO versions 20.4R1-EVO and later versions earlier than 20.4R3-S9-EVO; * 21.2-EVO versions earlier than 21.2R3-S7-EVO; * 21.3-EVO versions earlier than 21.3R3-S5-EVO; * 21.4-EVO versions earlier than 21.4R3-S5-EVO; * 22.1-EVO versions earlier than 22.1R3-S4-EVO; * 22.2-EVO versions earlier than 22.2R3-S3-EVO; * 22.3-EVO versions earlier than 22.3R3-S1-EVO; * 22.4-EVO versions earlier than 22.4R3-EVO; * 23.2-EVO versions earlier than 23.2R1-S2-EVO, 23.2R2-EVO; This issue does not affect Juniper Networks * Junos OS versions earlier than 20.4R1; * Junos OS Evolved versions earlier than 20.4R1-EVO. This is a related but separate issue than the one described in JSA79095.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-04-12 18:02 UTC
    CWE
    • CWE-1286 - Improper Validation of Syntactic Correctness of Input
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 20.4 , < 20.4R3-S9 (semver)
    Affected: 21.2 , < 21.2R3-S7 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3-S5 (semver)
    Affected: 22.1 , < 22.1R3-S4 (semver)
    Affected: 22.2 , < 22.2R3-S3 (semver)
    Affected: 22.3 , < 22.3R3-S1 (semver)
    Affected: 22.4 , < 22.4R3 (semver)
    Affected: 23.2 , < 23.2R1-S2, 23.2R2 (semver)
    Create a notification for this product.
    Juniper Networks Junos OS Evolved Affected: 20.4-EVO , < 20.4R3-S9-EVO (semver)
    Affected: 21.2-EVO , < 21.2R3-S7-EVO (semver)
    Affected: 21.3-EVO , < 21.3R3-S5-EVO (semver)
    Affected: 21.4-EVO , < 21.4R3-S5-EVO (semver)
    Affected: 22.1-EVO , < 22.1R3-S4-EVO (semver)
    Affected: 22.2-EVO , < 22.2R3-S3-EVO (semver)
    Affected: 22.3-EVO , < 22.3R3-S1-EVO (semver)
    Affected: 22.4-EVO , < 22.4R3-EVO (semver)
    Affected: 23.2-EVO , < 23.2R1-S2-EVO, 23.2R2-EVO (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 20.4 , < 20.4r3-s9 (custom)
    Affected: 21.2 , < 21.2r3-s7 (custom)
    Affected: 21.3 , < 21.3r3-s5 (custom)
    Affected: 21.4 , < 21.4r3-s5 (custom)
    Affected: 22.1 , < 22.1r3-s4 (custom)
    Affected: 22.2 , < 22.2r3-s3 (custom)
    Affected: 22.3 , < 22.3r3-s1 (custom)
    Affected: 22.4 , < 22.4r3 (custom)
    Affected: 23.2 , < 23.2r1-s2 (custom)
        cpe:2.3:o:juniper_networks:junos_os:20.4:*:*:*:*:*:*:*
    Create a notification for this product.
    juniper junos_os_evolved Affected: 20.4 , < 20.4r3-s9 (custom)
    Affected: 21.2 , < 21.2r3-s7 (custom)
    Affected: 21.3 , < 21.3r3-s5 (custom)
    Affected: 21.4 , < 21.4r3-s4 (custom)
    Affected: 22.1 , < 22.1r3-s4 (custom)
    Affected: 22.2 , < 22.2r3-s3 (custom)
        cpe:2.3:o:juniper:junos_os_evolved:22.3:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:22.4:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:23.2:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:20.4:r1:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:21.2:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:21.3:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:21.4:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:22.1:-:*:*:*:*:*:*
        cpe:2.3:o:juniper:junos_os_evolved:22.2:-:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-04-10 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:20.4:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4r3-s9",
                    "status": "affected",
                    "version": "20.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2r3-s7",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.3r3-s5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.4r3-s5",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1r3-s4",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.2r3-s3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3r3-s1",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4r3",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "23.2r1-s2",
                    "status": "affected",
                    "version": "23.2",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:juniper:junos_os_evolved:22.3:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:22.4:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:23.2:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:20.4:r1:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:21.2:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:21.3:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:21.4:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:22.1:-:*:*:*:*:*:*",
                  "cpe:2.3:o:juniper:junos_os_evolved:22.2:-:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os_evolved",
                "vendor": "juniper",
                "versions": [
                  {
                    "lessThan": "20.4r3-s9",
                    "status": "affected",
                    "version": "20.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2r3-s7",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.3r3-s5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.4r3-s4",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1r3-s4",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.2r3-s3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-21598",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-12T18:02:57.570562Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-31T14:32:30.418Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T22:27:36.007Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "http://supportportal.juniper.net/JSA75739"
              },
              {
                "tags": [
                  "technical-description",
                  "x_transferred"
                ],
                "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S9",
                  "status": "affected",
                  "version": "20.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S7",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S5",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S4",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3-S3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R3-S1",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R3",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "23.2R1-S2, 23.2R2",
                  "status": "affected",
                  "version": "23.2",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Junos OS Evolved",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S9-EVO",
                  "status": "affected",
                  "version": "20.4-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S7-EVO",
                  "status": "affected",
                  "version": "21.2-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5-EVO",
                  "status": "affected",
                  "version": "21.3-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S5-EVO",
                  "status": "affected",
                  "version": "21.4-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S4-EVO",
                  "status": "affected",
                  "version": "22.1-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3-S3-EVO",
                  "status": "affected",
                  "version": "22.2-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R3-S1-EVO",
                  "status": "affected",
                  "version": "22.3-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R3-EVO",
                  "status": "affected",
                  "version": "22.4-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "23.2R1-S2-EVO, 23.2R2-EVO",
                  "status": "affected",
                  "version": "23.2-EVO",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTo be exposed to this vulnerability BGP needs to be configured as in the following example, but no further options need to be enabled:\u003c/p\u003e\u003cp\u003e\u0026nbsp; [ protocols bgp group \u0026lt;group\u0026gt; neighbor ... ]\u003c/p\u003e"
                }
              ],
              "value": "To be exposed to this vulnerability BGP needs to be configured as in the following example, but no further options need to be enabled:\n\n\u00a0 [ protocols bgp group \u003cgroup\u003e neighbor ... ]"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Juniper SIRT would like to acknowledge and thank Matteo Memelli from Amazon for responsibly reporting this vulnerability."
            }
          ],
          "datePublic": "2024-04-10T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).\u003cbr\u003e\u003cbr\u003eIf a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute with a specifically malformed TLV, rpd will crash and restart.\u003cbr\u003e\u003cbr\u003eThis issue affects Juniper Networks\u003cbr\u003eJunos OS:\u003cbr\u003e\u003cul\u003e\u003cli\u003e20.4 versions 20.4R1 and later versions earlier than 20.4R3-S9;\u003c/li\u003e\u003cli\u003e21.2 versions earlier than 21.2R3-S7;\u003c/li\u003e\u003cli\u003e21.3 versions earlier than 21.3R3-S5;\u003c/li\u003e\u003cli\u003e21.4 versions earlier than 21.4R3-S5;\u003c/li\u003e\u003cli\u003e22.1 versions earlier than 22.1R3-S4;\u003c/li\u003e\u003cli\u003e22.2 versions earlier than 22.2R3-S3;\u003c/li\u003e\u003cli\u003e22.3 versions earlier than 22.3R3-S1;\u003c/li\u003e\u003cli\u003e22.4 versions earlier than 22.4R3;\u003c/li\u003e\u003cli\u003e23.2 versions earlier than 23.2R1-S2, 23.2R2;\u003c/li\u003e\u003c/ul\u003e\u003cbr\u003eJunos OS Evolved:\u003cbr\u003e\u003cul\u003e\u003cli\u003e20.4-EVO versions 20.4R1-EVO and later versions earlier than 20.4R3-S9-EVO;\u003c/li\u003e\u003cli\u003e21.2-EVO versions earlier than 21.2R3-S7-EVO;\u003c/li\u003e\u003cli\u003e21.3-EVO versions earlier than 21.3R3-S5-EVO;\u003c/li\u003e\u003cli\u003e21.4-EVO versions earlier than 21.4R3-S5-EVO;\u003c/li\u003e\u003cli\u003e22.1-EVO versions earlier than 22.1R3-S4-EVO;\u003c/li\u003e\u003cli\u003e22.2-EVO versions earlier than 22.2R3-S3-EVO;\u003c/li\u003e\u003cli\u003e22.3-EVO versions earlier than 22.3R3-S1-EVO;\u003c/li\u003e\u003cli\u003e22.4-EVO versions earlier than 22.4R3-EVO;\u003c/li\u003e\u003cli\u003e23.2-EVO versions earlier than 23.2R1-S2-EVO, 23.2R2-EVO;\u003c/li\u003e\u003c/ul\u003e\u003cbr\u003eThis issue does not affect Juniper Networks\u003cbr\u003e\u003cul\u003e\u003cli\u003eJunos OS versions earlier than 20.4R1;\u003c/li\u003e\u003cli\u003eJunos OS Evolved versions earlier than 20.4R1-EVO.\u003c/li\u003e\u003c/ul\u003e\u003cbr\u003eThis is a related but separate issue than the one described in JSA79095.\u003cbr\u003e"
                }
              ],
              "value": "An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).\n\nIf a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute with a specifically malformed TLV, rpd will crash and restart.\n\nThis issue affects Juniper Networks\nJunos OS:\n  *  20.4 versions 20.4R1 and later versions earlier than 20.4R3-S9;\n  *  21.2 versions earlier than 21.2R3-S7;\n  *  21.3 versions earlier than 21.3R3-S5;\n  *  21.4 versions earlier than 21.4R3-S5;\n  *  22.1 versions earlier than 22.1R3-S4;\n  *  22.2 versions earlier than 22.2R3-S3;\n  *  22.3 versions earlier than 22.3R3-S1;\n  *  22.4 versions earlier than 22.4R3;\n  *  23.2 versions earlier than 23.2R1-S2, 23.2R2;\n\n\n\nJunos OS Evolved:\n  *  20.4-EVO versions 20.4R1-EVO and later versions earlier than 20.4R3-S9-EVO;\n  *  21.2-EVO versions earlier than 21.2R3-S7-EVO;\n  *  21.3-EVO versions earlier than 21.3R3-S5-EVO;\n  *  21.4-EVO versions earlier than 21.4R3-S5-EVO;\n  *  22.1-EVO versions earlier than 22.1R3-S4-EVO;\n  *  22.2-EVO versions earlier than 22.2R3-S3-EVO;\n  *  22.3-EVO versions earlier than 22.3R3-S1-EVO;\n  *  22.4-EVO versions earlier than 22.4R3-EVO;\n  *  23.2-EVO versions earlier than 23.2R1-S2-EVO, 23.2R2-EVO;\n\n\n\nThis issue does not affect Juniper Networks\n  *  Junos OS versions earlier than 20.4R1;\n  *  Junos OS Evolved versions earlier than 20.4R1-EVO.\n\n\n\nThis is a related but separate issue than the one described in JSA79095."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1286",
                  "description": "CWE-1286 Improper Validation of Syntactic Correctness of Input",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-16T19:53:00.228Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "http://supportportal.juniper.net/JSA75739"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: \u003c/p\u003e\u003cp\u003eJunos OS: 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S3, 22.3R3-S1, 22.4R3, 23.2R1-S2, 23.2R2, 23.4R1, and all subsequent releases;\u003c/p\u003e\u003cp\u003eJunos OS Evolved: 20.4R3-S9-EVO, 21.2R3-S7-EVO, 21.3R3-S5-EVO, 21.4R3-S5-EVO, 22.1R3-S4-EVO, 22.2R3-S3-EVO, 22.3R3-S1-EVO, 22.4R3-EVO, 23.2R1-S2-EVO, 23.2R2-EVO, 23.4R1-EVO, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: \n\nJunos OS: 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S3, 22.3R3-S1, 22.4R3, 23.2R1-S2, 23.2R2, 23.4R1, and all subsequent releases;\n\nJunos OS Evolved: 20.4R3-S9-EVO, 21.2R3-S7-EVO, 21.3R3-S5-EVO, 21.4R3-S5-EVO, 22.1R3-S4-EVO, 22.2R3-S3-EVO, 22.3R3-S1-EVO, 22.4R3-EVO, 23.2R1-S2-EVO, 23.2R2-EVO, 23.4R1-EVO, and all subsequent releases."
            }
          ],
          "source": {
            "advisory": "JSA75739",
            "defect": [
              "1760356"
            ],
            "discovery": "USER"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-04-10T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThere are no known workarounds for this issue.\u003c/p\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2024-21598",
        "datePublished": "2024-04-12T14:54:23.761Z",
        "dateReserved": "2023-12-27T19:38:25.705Z",
        "dateUpdated": "2024-08-01T22:27:36.007Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-44199 (GCVE-0-2023-44199)

    Vulnerability from cvelistv5 โ€“ Published: 2023-10-12 23:05 โ€“ Updated: 2024-09-18 14:33
    VLAI
    Title
    Junos OS: MX Series: In a PTP scenario a prolonged routing protocol churn can trigger an FPC reboot
    Summary
    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). On Junos MX Series platforms with Precision Time Protocol (PTP) configured, a prolonged routing protocol churn can lead to an FPC crash and restart. This issue affects Juniper Networks Junos OS on MX Series: * All versions prior to 20.4R3-S4; * 21.1 version 21.1R1 and later versions; * 21.2 versions prior to 21.2R3-S2; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3; * 22.1 versions prior to 22.1R3; * 22.2 versions prior to 22.2R1-S1, 22.2R2.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-09-18 14:33 UTC
    CWE
    • CWE-754 - Improper Check for Unusual or Exceptional Conditions
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 0 , < 20.4R3-S4 (semver)
    Affected: 21.1R1 , < 21.1* (semver)
    Affected: 21.2 , < 21.2R3-S2 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3 (semver)
    Affected: 22.1 , < 22.1R3 (semver)
    Affected: 22.2 , < 22.2R1-S1, 22.2R2 (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 20.4r3-s4 (semver)
    Affected: 21.1r1 , < 21.1* (semver)
    Affected: 21.2 , < 21.2r3-s2 (semver)
    Affected: 21.3 , < 21.3r3-s5 (semver)
    Affected: 21.4 , < 21.4r3 (semver)
    Affected: 22.1 , < 22.1r3 (semver)
    Affected: 22.2 , < 22.2r1-s1,22.2r2 (semver)
        cpe:2.3:a:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-10-11 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:59:51.383Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA73165"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4r3-s4",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.1*",
                    "status": "affected",
                    "version": "21.1r1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2r3-s2",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3r3-s5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4r3",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1r3",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r1-s1,22.2r2",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-44199",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-18T14:33:42.839560Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T14:33:48.227Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "MX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.1*",
                  "status": "affected",
                  "version": "21.1R1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S2",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R1-S1, 22.2R2",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTo be exposed to this issue an FPC must have at least one interface with PTP configured like in the following example:\u003c/p\u003e \u003ctt\u003e[ protocols ptp master/slave interface ]\u003c/tt\u003e"
                }
              ],
              "value": "To be exposed to this issue an FPC must have at least one interface with PTP configured like in the following example:\n\n [ protocols ptp master/slave interface ]"
            }
          ],
          "datePublic": "2023-10-11T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eAn Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).\u003c/p\u003e\u003cp\u003eOn Junos MX Series platforms with Precision Time Protocol (PTP) configured, a prolonged routing protocol churn can lead to an FPC crash and restart.\u003c/p\u003e\u003cp\u003eThis issue affects Juniper Networks Junos OS on MX Series:\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003eAll versions prior to 20.4R3-S4;\u003c/li\u003e\u003cli\u003e21.1 version 21.1R1 and later versions;\u003c/li\u003e\u003cli\u003e21.2 versions prior to 21.2R3-S2;\u003c/li\u003e\u003cli\u003e21.3 versions prior to 21.3R3-S5;\u003c/li\u003e\u003cli\u003e21.4 versions prior to 21.4R3;\u003c/li\u003e\u003cli\u003e22.1 versions prior to 22.1R3;\u003c/li\u003e\u003cli\u003e22.2 versions prior to 22.2R1-S1, 22.2R2.\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e\n\n"
                }
              ],
              "value": "\nAn Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).\n\nOn Junos MX Series platforms with Precision Time Protocol (PTP) configured, a prolonged routing protocol churn can lead to an FPC crash and restart.\n\nThis issue affects Juniper Networks Junos OS on MX Series:\n\n\n\n  *  All versions prior to 20.4R3-S4;\n  *  21.1 version 21.1R1 and later versions;\n  *  21.2 versions prior to 21.2R3-S2;\n  *  21.3 versions prior to 21.3R3-S5;\n  *  21.4 versions prior to 21.4R3;\n  *  22.1 versions prior to 22.1R3;\n  *  22.2 versions prior to 22.2R1-S1, 22.2R2.\n\n\n\n\n\n\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-754",
                  "description": "CWE-754 Improper Check for Unusual or Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-12T23:05:52.303Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.juniper.net/JSA73165"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S4, 21.2R3-S2, 21.3R3-S5, 21.4R3, 22.1R3, 22.2R1-S1, 22.2R2, 22.3R1, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S4, 21.2R3-S2, 21.3R3-S5, 21.4R3, 22.1R3, 22.2R1-S1, 22.2R2, 22.3R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "advisory": "JSA73165",
            "defect": [
              "1653681"
            ],
            "discovery": "USER"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-10-11T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS: MX Series: In a PTP scenario a prolonged routing protocol churn can trigger an FPC reboot",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThere are no known workarounds for this issue.\u003c/p\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-44199",
        "datePublished": "2023-10-12T23:05:52.303Z",
        "dateReserved": "2023-09-26T19:30:32.350Z",
        "dateUpdated": "2024-09-18T14:33:48.227Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-44198 (GCVE-0-2023-44198)

    Vulnerability from cvelistv5 โ€“ Published: 2023-10-12 23:05 โ€“ Updated: 2024-09-18 14:41
    VLAI
    Title
    Junos OS: SRX Series and MX Series: SIP ALG doesn't drop specifically malformed retransmitted SIP packets
    Summary
    An Improper Check for Unusual or Exceptional Conditions vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated network-based attacker to cause an integrity impact in connected networks. If the SIP ALG is configured and a device receives a specifically malformed SIP packet, the device prevents this packet from being forwarded, but any subsequently received retransmissions of the same packet are forwarded as if they were valid. This issue affects Juniper Networks Junos OS on SRX Series and MX Series: * 20.4 versions prior to 20.4R3-S5; * 21.1 versions prior to 21.1R3-S4; * 21.2 versions prior to 21.2R3-S4; * 21.3 versions prior to 21.3R3-S3; * 21.4 versions prior to 21.4R3-S2; * 22.1 versions prior to 22.1R2-S2, 22.1R3; * 22.2 versions prior to 22.2R2-S1, 22.2R3; * 22.3 versions prior to 22.3R1-S2, 22.3R2. This issue doesn't not affected releases prior to 20.4R1.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-09-18 14:36 UTC
    CWE
    • CWE-754 - Improper Check for Unusual or Exceptional Conditions
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 20.4 , < 20.4R3-S5 (semver)
    Affected: 21.1 , < 21.1R3-S4 (semver)
    Affected: 21.2 , < 21.2R3-S4 (semver)
    Affected: 21.3 , < 21.3R3-S3 (semver)
    Affected: 21.4 , < 21.4R3-S2 (semver)
    Affected: 22.1 , < 22.1R2-S2, 22.1R3 (semver)
    Affected: 22.2 , < 22.2R2-S1, 22.2R3 (semver)
    Affected: 22.3 , < 22.3R1-S2, 22.3R2 (semver)
    Affected: 0 , < 20.4R1 (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 20.4 , < 20.4r3-s5 (semver)
    Affected: 21.1 , < 21.1r3-s4 (semver)
    Affected: 21.2 , < 21.2r3-s4 (semver)
    Affected: 21.3 , < 21.3r3-s3 (semver)
    Affected: 21.4 , < 21.4r3-s2 (semver)
    Affected: 22.1 , < 22.1r2-s2,22.1r3 (semver)
    Affected: 22.2 , < 22.2r2-s122.2r3 (semver)
    Affected: 22.3 , < 22.3r1-s2.22.3r2 (semver)
    Affected: 0 , < 20.4r1 (semver)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-10-11 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:59:51.680Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA73164"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4r3-s5",
                    "status": "affected",
                    "version": "20.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.1r3-s4",
                    "status": "affected",
                    "version": "21.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2r3-s4",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3r3-s3",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4r3-s2",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1r2-s2,22.1r3",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r2-s122.2r3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r1-s2.22.3r2",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "20.4r1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-44198",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-18T14:36:59.623824Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T14:41:11.841Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "SRX Series",
                "MX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S5",
                  "status": "affected",
                  "version": "20.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.1R3-S4",
                  "status": "affected",
                  "version": "21.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S4",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S3",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S2",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R2-S2, 22.1R3",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R2-S1, 22.2R3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R1-S2, 22.3R2",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "20.4R1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eTo be affected the SIP ALG needs to be enabled, either implicitly / by default or by way of configuration. Please verify on SRX, and MX with SPC3 with:\u003c/p\u003e\u003ccode\u003euser@host\u0026gt; show security alg status | match sip\u003c/code\u003e\u003cbr\u003e\u003ccode\u003eSIP : Enabled\u003c/code\u003e\u003cbr\u003e\u003cp\u003ePlease verify on MX whether the following is configured:\u003c/p\u003e\u003ccode\u003e[ services ... rule \u0026lt;rule-name\u0026gt; (term \u0026lt;term-name\u0026gt; ) from/match application/application-set \u0026lt;name\u0026gt; ]\u003c/code\u003e\u003cbr\u003e\u003cp\u003ewhere either\u003c/p\u003e\u003ccode\u003ea. name = junos-sip or\u003c/code\u003e\u003cbr\u003e\u003cp\u003ean application or application-set refers to SIP:\u003c/p\u003e\u003ccode\u003eb. [ applications application \u0026lt;name\u0026gt; application-protocol sip ] or\u003c/code\u003e\u003cbr\u003e\u003ccode\u003ec. [ applications application-set \u0026lt;name\u0026gt; application junos-sip ]\u003c/code\u003e\n\n"
                }
              ],
              "value": "\nTo be affected the SIP ALG needs to be enabled, either implicitly / by default or by way of configuration. Please verify on SRX, and MX with SPC3 with:\n\nuser@host\u003e show security alg status | match sip\nSIP : Enabled\nPlease verify on MX whether the following is configured:\n\n[ services ... rule \u003crule-name\u003e (term \u003cterm-name\u003e ) from/match application/application-set \u003cname\u003e ]\nwhere either\n\na. name = junos-sip or\nan application or application-set refers to SIP:\n\nb. [ applications application \u003cname\u003e application-protocol sip ] or\nc. [ applications application-set \u003cname\u003e application junos-sip ]\n\n"
            }
          ],
          "datePublic": "2023-10-11T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eAn Improper Check for Unusual or Exceptional Conditions vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated network-based attacker to cause an integrity impact in connected networks.\u003c/p\u003e\u003cp\u003eIf the SIP ALG is configured and a device receives a specifically malformed SIP packet, the device prevents this packet from being forwarded, but any subsequently received retransmissions of the same packet are forwarded as if they were valid.\u003c/p\u003e\u003cp\u003eThis issue affects Juniper Networks Junos OS on SRX Series and MX Series:\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003e20.4 versions prior to 20.4R3-S5;\u003c/li\u003e\u003cli\u003e21.1 versions prior to 21.1R3-S4;\u003c/li\u003e\u003cli\u003e21.2 versions prior to 21.2R3-S4;\u003c/li\u003e\u003cli\u003e21.3 versions prior to 21.3R3-S3;\u003c/li\u003e\u003cli\u003e21.4 versions prior to 21.4R3-S2;\u003c/li\u003e\u003cli\u003e22.1 versions prior to 22.1R2-S2, 22.1R3;\u003c/li\u003e\u003cli\u003e22.2 versions prior to 22.2R2-S1, 22.2R3;\u003c/li\u003e\u003cli\u003e22.3 versions prior to 22.3R1-S2, 22.3R2.\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eThis issue doesn\u0027t not affected releases prior to 20.4R1.\u003c/p\u003e\n\n"
                }
              ],
              "value": "\nAn Improper Check for Unusual or Exceptional Conditions vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated network-based attacker to cause an integrity impact in connected networks.\n\nIf the SIP ALG is configured and a device receives a specifically malformed SIP packet, the device prevents this packet from being forwarded, but any subsequently received retransmissions of the same packet are forwarded as if they were valid.\n\nThis issue affects Juniper Networks Junos OS on SRX Series and MX Series:\n\n\n\n  *  20.4 versions prior to 20.4R3-S5;\n  *  21.1 versions prior to 21.1R3-S4;\n  *  21.2 versions prior to 21.2R3-S4;\n  *  21.3 versions prior to 21.3R3-S3;\n  *  21.4 versions prior to 21.4R3-S2;\n  *  22.1 versions prior to 22.1R2-S2, 22.1R3;\n  *  22.2 versions prior to 22.2R2-S1, 22.2R3;\n  *  22.3 versions prior to 22.3R1-S2, 22.3R2.\n\n\n\n\nThis issue doesn\u0027t not affected releases prior to 20.4R1.\n\n\n\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-754",
                  "description": "CWE-754 Improper Check for Unusual or Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-12T23:05:42.031Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.juniper.net/JSA73164"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S5, 21.1R3-S4, 21.2R3-S4, 21.3R3-S3, 21.4R3-S2, 22.1R2-S2, 22.1R3, 22.2R2-S1, 22.2R3, 22.3R1-S2, 22.3R2, 22.4R1, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S5, 21.1R3-S4, 21.2R3-S4, 21.3R3-S3, 21.4R3-S2, 22.1R2-S2, 22.1R3, 22.2R2-S1, 22.2R3, 22.3R1-S2, 22.3R2, 22.4R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "advisory": "JSA73164",
            "defect": [
              "1693379"
            ],
            "discovery": "INTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-10-11T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS: SRX Series and MX Series: SIP ALG doesn\u0027t drop specifically malformed retransmitted SIP packets",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThere are no known workarounds for this issue.\u003c/p\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-44198",
        "datePublished": "2023-10-12T23:05:42.031Z",
        "dateReserved": "2023-09-26T19:30:32.350Z",
        "dateUpdated": "2024-09-18T14:41:11.841Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-44192 (GCVE-0-2023-44192)

    Vulnerability from cvelistv5 โ€“ Published: 2023-10-12 23:03 โ€“ Updated: 2024-09-18 14:21
    VLAI
    Title
    Junos OS: QFX5000 Series: DMA memory leak is observed when specific DHCP packets are transmitted over pseudo-VTEP
    Summary
    An Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause memory leak, leading to Denial of Service (DoS). On all Junos OS QFX5000 Series platforms, when pseudo-VTEP (Virtual Tunnel End Point) is configured under EVPN-VXLAN scenario, and specific DHCP packets are transmitted, DMA memory leak is observed. Continuous receipt of these specific DHCP packets will cause memory leak to reach 99% and then cause the protocols to stop working and traffic is impacted, leading to Denial of Service (DoS) condition. A manual reboot of the system recovers from the memory leak. To confirm the memory leak, monitor for "sheaf:possible leak" and "vtep not found" messages in the logs. This issue affects: Juniper Networks Junos OS QFX5000 Series: * All versions prior to 20.4R3-S6; * 21.1 versions prior to 21.1R3-S5; * 21.2 versions prior to 21.2R3-S5; * 21.3 versions prior to 21.3R3-S4; * 21.4 versions prior to 21.4R3-S3; * 22.1 versions prior to 22.1R3-S2; * 22.2 versions prior to 22.2R2-S2, 22.2R3; * 22.3 versions prior to 22.3R2-S1, 22.3R3; * 22.4 versions prior to 22.4R1-S2, 22.4R2.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-09-18 14:03 UTC
    CWE
    • CWE-20 - Improper Input Validation
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 0 , < 20.4R3-S6 (semver)
    Affected: 21.1 , < 21.1R3-S5 (semver)
    Affected: 21.2 , < 21.2R3-S5 (semver)
    Affected: 21.3 , < 21.3R3-S4 (semver)
    Affected: 21.4 , < 21.4R3-S3 (semver)
    Affected: 22.1 , < 22.1R3-S2 (semver)
    Affected: 22.2 , < 22.2R2-S2, 22.2R3 (semver)
    Affected: 22.3 , < 22.3R2-S1, 22.3R3 (semver)
    Affected: 22.4 , < 22.4R1-S2, 22.4R2 (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 20.4r3-s6 (semver)
    Affected: 21.1 , < 21.1r3-s5 (semver)
    Affected: 21.2 , < 21.2r3-s5 (semver)
    Affected: 21.3 , < 21.3r3-s4 (semver)
    Affected: 21.4 , < 21.4r3-s3 (semver)
    Affected: 22.1 , < 22.1r3-s2 (semver)
    Affected: 22.2 , < 22.2r2-s2 (semver)
    Affected: 22.2 , < 22.2r3 (semver)
    Affected: 22.3 , < 22.3r2-s1 (custom)
    Affected: 22.3 , < 22..3r3 (custom)
    Affected: 22.4 , < 22.4r2-s2 (custom)
    Affected: 22.4 , < 22.4r2 (custom)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-10-11 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:59:51.573Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA73156"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4r3-s6",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.1r3-s5",
                    "status": "affected",
                    "version": "21.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2r3-s5",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3r3-s4",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4r3-s3",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1r3-s2",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r2-s2",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r2-s1",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22..3r3",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4r2-s2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4r2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-44192",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-18T14:03:43.315994Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T14:21:02.483Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "QFX5000 Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.1R3-S5",
                  "status": "affected",
                  "version": "21.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S5",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S4",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S3",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S2",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R2-S2, 22.2R3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R2-S1, 22.3R3",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R1-S2, 22.4R2",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eFor this issue to surface, shared tunnels need to be configured under EVPN-VXLAN scenario.\u003c/p\u003e\u003ctt\u003e[ forwarding-options evpn-vxlan shared-tunnels ]\u003c/tt\u003e"
                }
              ],
              "value": "For this issue to surface, shared tunnels need to be configured under EVPN-VXLAN scenario.\n\n[ forwarding-options evpn-vxlan shared-tunnels ]"
            }
          ],
          "datePublic": "2023-10-11T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eAn Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause memory leak, leading to Denial of Service (DoS).\u003c/p\u003e\u003cp\u003eOn all Junos OS QFX5000 Series platforms, when pseudo-VTEP (Virtual Tunnel End Point) is configured under EVPN-VXLAN scenario, and specific DHCP packets are transmitted, DMA memory leak is observed. Continuous receipt of these specific DHCP packets will cause memory leak to reach 99% and then cause the protocols to stop working and traffic is impacted, leading to Denial of Service (DoS) condition. A manual reboot of the system recovers from the memory leak.\u003c/p\u003e\u003cp\u003eTo confirm the memory leak, monitor for \"sheaf:possible leak\" and \"vtep not found\" messages in the logs.\u003c/p\u003e\u003cp\u003eThis issue affects:\u003c/p\u003e\u003cp\u003eJuniper Networks Junos OS QFX5000 Series:\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003eAll versions prior to 20.4R3-S6;\u003c/li\u003e\u003cli\u003e21.1 versions prior to 21.1R3-S5;\u003c/li\u003e\u003cli\u003e21.2 versions prior to 21.2R3-S5;\u003c/li\u003e\u003cli\u003e21.3 versions prior to 21.3R3-S4;\u003c/li\u003e\u003cli\u003e21.4 versions prior to 21.4R3-S3;\u003c/li\u003e\u003cli\u003e22.1 versions prior to 22.1R3-S2;\u003c/li\u003e\u003cli\u003e22.2 versions prior to 22.2R2-S2, 22.2R3;\u003c/li\u003e\u003cli\u003e22.3 versions prior to 22.3R2-S1, 22.3R3;\u003c/li\u003e\u003cli\u003e22.4 versions prior to 22.4R1-S2, 22.4R2.\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e\n\n"
                }
              ],
              "value": "\nAn Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause memory leak, leading to Denial of Service (DoS).\n\nOn all Junos OS QFX5000 Series platforms, when pseudo-VTEP (Virtual Tunnel End Point) is configured under EVPN-VXLAN scenario, and specific DHCP packets are transmitted, DMA memory leak is observed. Continuous receipt of these specific DHCP packets will cause memory leak to reach 99% and then cause the protocols to stop working and traffic is impacted, leading to Denial of Service (DoS) condition. A manual reboot of the system recovers from the memory leak.\n\nTo confirm the memory leak, monitor for \"sheaf:possible leak\" and \"vtep not found\" messages in the logs.\n\nThis issue affects:\n\nJuniper Networks Junos OS QFX5000 Series:\n\n\n\n  *  All versions prior to 20.4R3-S6;\n  *  21.1 versions prior to 21.1R3-S5;\n  *  21.2 versions prior to 21.2R3-S5;\n  *  21.3 versions prior to 21.3R3-S4;\n  *  21.4 versions prior to 21.4R3-S3;\n  *  22.1 versions prior to 22.1R3-S2;\n  *  22.2 versions prior to 22.2R2-S2, 22.2R3;\n  *  22.3 versions prior to 22.3R2-S1, 22.3R3;\n  *  22.4 versions prior to 22.4R1-S2, 22.4R2.\n\n\n\n\n\n\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-12T23:03:45.324Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.juniper.net/JSA73156"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S6, 21.1R3-S5, 21.2R3-S5, 21.3R3-S4, 21.4R3-S3, 22.1R3-S2, 22.2R2-S2, 22.2R3, 22.3R2-S1, 22.3R3, 22.4R1-S2, 22.4R2, 23.2R1, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S6, 21.1R3-S5, 21.2R3-S5, 21.3R3-S4, 21.4R3-S3, 22.1R3-S2, 22.2R2-S2, 22.2R3, 22.3R2-S1, 22.3R3, 22.4R1-S2, 22.4R2, 23.2R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "advisory": "JSA73156",
            "defect": [
              "1708370"
            ],
            "discovery": "USER"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-10-11T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS: QFX5000 Series: DMA memory leak is observed when specific DHCP packets are transmitted over pseudo-VTEP",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThere are no known workarounds for this issue.\u003c/p\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-44192",
        "datePublished": "2023-10-12T23:03:45.324Z",
        "dateReserved": "2023-09-26T19:30:27.954Z",
        "dateUpdated": "2024-09-18T14:21:02.483Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-44191 (GCVE-0-2023-44191)

    Vulnerability from cvelistv5 โ€“ Published: 2023-10-12 23:03 โ€“ Updated: 2024-09-19 14:14
    VLAI
    Title
    Junos OS: QFX5000 Series and EX4000 Series: Denial of Service (DoS) on a large scale VLAN due to PFE hogging
    Summary
    An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all Junos OS QFX5000 Series and EX4000 Series platforms, when a high number of VLANs are configured, a specific DHCP packet will cause PFE hogging which will lead to dropping of socket connections. This issue affects: Juniper Networks Junos OS on QFX5000 Series and EX4000 Series * 21.1 versions prior to 21.1R3-S5; * 21.2 versions prior to 21.2R3-S5; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S4; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S1; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2. This issue does not affect Juniper Networks Junos OS versions prior to 21.1R1
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-09-19 14:10 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Unaffected: 0 , < 21.1R1 (semver)
    Affected: 21.1 , < 21.1R3-S5 (semver)
    Affected: 21.2 , < 21.2R3-S5 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3-S4 (semver)
    Affected: 22.1 , < 22.1R3-S3 (semver)
    Affected: 22.2 , < 22.2R3-S1 (semver)
    Affected: 22.3 , < 22.3R2-S2, 22.3R3 (semver)
    Affected: 22.4 , < 22.4R2 (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 21.1r1 (semver)
    Affected: 21.1 , < 21.1r3-s5 (semver)
    Affected: 21.2 , < 21.2r3-s5 (semver)
    Affected: 21.3 , < 21.3r3-s5 (semver)
    Affected: 21.4 , < 21.4r3-s4 (semver)
    Affected: 22.1 , < ss.1r3-s3 (semver)
    Affected: 22.2 , < 22.2r3-s1 (semver)
    Affected: 22.3 , < 22.3r2-s2 (semver)
    Affected: 22.4 , < 22.4r2 (semver)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-10-11 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:59:51.578Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA73155"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "21.1r1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.1r3-s5",
                    "status": "affected",
                    "version": "21.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2r3-s5",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3r3-s5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4r3-s4",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "ss.1r3-s3",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r3-s1",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r2-s2",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.4r2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-44191",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-19T14:10:10.810352Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-19T14:14:17.438Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "QFX5000 Series",
                "EX4000 Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "21.1R1",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.1R3-S5",
                  "status": "affected",
                  "version": "21.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S5",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S4",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S3",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3-S1",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R2-S2, 22.3R3",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R2",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "datePublic": "2023-10-11T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eAn Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).\u003c/p\u003e\u003cp\u003eOn all Junos OS QFX5000 Series and EX4000 Series platforms, when a high number of VLANs are configured, a specific DHCP packet will cause PFE hogging which will lead to dropping of socket connections.\u003c/p\u003e\u003cp\u003eThis issue affects:\u003c/p\u003e\u003cp\u003eJuniper Networks Junos OS on QFX5000 Series and EX4000 Series\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003e21.1 versions prior to 21.1R3-S5;\u003c/li\u003e\u003cli\u003e21.2 versions prior to 21.2R3-S5;\u003c/li\u003e\u003cli\u003e21.3 versions prior to 21.3R3-S5;\u003c/li\u003e\u003cli\u003e21.4 versions prior to 21.4R3-S4;\u003c/li\u003e\u003cli\u003e22.1 versions prior to 22.1R3-S3;\u003c/li\u003e\u003cli\u003e22.2 versions prior to 22.2R3-S1;\u003c/li\u003e\u003cli\u003e22.3 versions prior to 22.3R2-S2, 22.3R3;\u003c/li\u003e\u003cli\u003e22.4 versions prior to 22.4R2.\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eThis issue does not affect Juniper Networks Junos OS versions prior to 21.1R1\u003c/p\u003e\n\n"
                }
              ],
              "value": "\nAn Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).\n\nOn all Junos OS QFX5000 Series and EX4000 Series platforms, when a high number of VLANs are configured, a specific DHCP packet will cause PFE hogging which will lead to dropping of socket connections.\n\nThis issue affects:\n\nJuniper Networks Junos OS on QFX5000 Series and EX4000 Series\n\n\n\n  *  21.1 versions prior to 21.1R3-S5;\n  *  21.2 versions prior to 21.2R3-S5;\n  *  21.3 versions prior to 21.3R3-S5;\n  *  21.4 versions prior to 21.4R3-S4;\n  *  22.1 versions prior to 22.1R3-S3;\n  *  22.2 versions prior to 22.2R3-S1;\n  *  22.3 versions prior to 22.3R2-S2, 22.3R3;\n  *  22.4 versions prior to 22.4R2.\n\n\n\n\nThis issue does not affect Juniper Networks Junos OS versions prior to 21.1R1\n\n\n\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-12T23:03:20.746Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.juniper.net/JSA73155"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: Junos OS 21.2R3-S5, 21.3R3-S5, 21.4R3-S4, 22.1R3-S3, 22.2R3-S1, 22.3R2-S2, 22.3R3, 22.4R2, 23.2R1, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 21.2R3-S5, 21.3R3-S5, 21.4R3-S4, 22.1R3-S3, 22.2R3-S1, 22.3R2-S2, 22.3R3, 22.4R2, 23.2R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "advisory": "JSA73155",
            "defect": [
              "1711644"
            ],
            "discovery": "USER"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-10-11T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS: QFX5000 Series and EX4000 Series: Denial of Service (DoS) on a large scale VLAN due to PFE hogging",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThere are no known workarounds for this issue.\u003c/p\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-44191",
        "datePublished": "2023-10-12T23:03:20.746Z",
        "dateReserved": "2023-09-26T19:30:27.953Z",
        "dateUpdated": "2024-09-19T14:14:17.438Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-36843 (GCVE-0-2023-36843)

    Vulnerability from cvelistv5 โ€“ Published: 2023-10-12 22:58 โ€“ Updated: 2024-09-18 17:53
    VLAI
    Title
    Junos OS: SRX Series: The PFE will crash on receiving malformed SSL traffic when Sky ATP is enabled
    Summary
    An Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby resulting in a Denial of Service (DoS). Upon receiving malformed SSL traffic, the PFE crashes. A manual restart will be needed to recover the device. This issue only affects devices with Juniper Networks Advanced Threat Prevention (ATP) Cloud enabled with Encrypted Traffic Insights (configured via โ€˜security-metadata-streaming policyโ€™). This issue affects Juniper Networks Junos OS: * All versions prior to 20.4R3-S8, 20.4R3-S9; * 21.1 version 21.1R1 and later versions; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3;
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-09-18 17:43 UTC
    CWE
    • CWE-168 - Improper Handling of Inconsistent Special Elements
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 0 , < 20.4R3-S8 (semver)
    Affected: 21.1R1 , < 21.1* (semver)
    Affected: 21.2 , < 21.2R3-S6 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3-S5 (semver)
    Affected: 22.1 , < 22.1R3-S4 (semver)
    Affected: 22.2 , < 22.2R3-S2 (semver)
    Affected: 22.3 , < 22.3R2-S2, 22.3R3 (semver)
    Affected: 22.4 , < 22.4R2-S1, 22.4R3 (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 20.4r3-s8 (semver)
    Affected: 21.1r1 , < 21.1 (semver)
    Affected: 21.2 , < 21.2r3-s6 (semver)
    Affected: 21.3 , < 21.3r3-s5 (semver)
    Affected: 21.4 , < 21.4r3-s5 (semver)
    Affected: 22.1 , < 22.1r3-s2 (semver)
    Affected: 22.2 , < 22.2r3-s2 (semver)
    Affected: 22.3 , < 22.3r2-s2 (semver)
    Affected: 22.3 , < 22.3r3 (semver)
    Affected: 22.4 , < 22.4r2-s2 (semver)
    Affected: 22.4 , < 22.4r3 (semver)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-10-11 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:01:09.673Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA73174"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4r3-s8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.1",
                    "status": "affected",
                    "version": "21.1r1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2r3-s6",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3r3-s5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4r3-s5",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1r3-s2",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r3-s2",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r2-s2",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r3",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.4r2-s2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.4r3",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-36843",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-18T17:43:08.375533Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-168",
                    "description": "CWE-168 Improper Handling of Inconsistent Special Elements",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T17:53:30.073Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "SRX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.1*",
                  "status": "affected",
                  "version": "21.1R1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S6",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S5",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S4",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3-S2",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R2-S2, 22.3R3",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R2-S1, 22.4R3",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe below command configures security-metadata-streaming:\u003c/p\u003e\u003ctt\u003e[ set services security-metadata-streaming policy ]\u003c/tt\u003e"
                }
              ],
              "value": "The below command configures security-metadata-streaming:\n\n[ set services security-metadata-streaming policy ]"
            }
          ],
          "datePublic": "2023-10-11T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eAn Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby resulting in a Denial of Service (DoS).\u003c/p\u003e\u003cp\u003eUpon receiving malformed SSL traffic, the PFE crashes. A manual restart will be needed to recover the device.\u003c/p\u003e\u003cp\u003eThis issue only affects devices with Juniper Networks Advanced Threat Prevention (ATP) Cloud enabled with Encrypted Traffic Insights (configured via \u2018security-metadata-streaming policy\u2019).\u003c/p\u003e\u003cp\u003eThis issue affects Juniper Networks Junos OS:\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003eAll versions prior to 20.4R3-S8, 20.4R3-S9;\u003c/li\u003e\u003cli\u003e21.1 version 21.1R1 and later versions;\u003c/li\u003e\u003cli\u003e21.2 versions prior to 21.2R3-S6;\u003c/li\u003e\u003cli\u003e21.3 versions prior to 21.3R3-S5;\u003c/li\u003e\u003cli\u003e21.4 versions prior to 21.4R3-S5;\u003c/li\u003e\u003cli\u003e22.1 versions prior to 22.1R3-S4;\u003c/li\u003e\u003cli\u003e22.2 versions prior to 22.2R3-S2;\u003c/li\u003e\u003cli\u003e22.3 versions prior to 22.3R2-S2, 22.3R3;\u003c/li\u003e\u003cli\u003e22.4 versions prior to 22.4R2-S1, 22.4R3;\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e\n\n"
                }
              ],
              "value": "\nAn Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby resulting in a Denial of Service (DoS).\n\nUpon receiving malformed SSL traffic, the PFE crashes. A manual restart will be needed to recover the device.\n\nThis issue only affects devices with Juniper Networks Advanced Threat Prevention (ATP) Cloud enabled with Encrypted Traffic Insights (configured via \u2018security-metadata-streaming policy\u2019).\n\nThis issue affects Juniper Networks Junos OS:\n\n\n\n  *  All versions prior to 20.4R3-S8, 20.4R3-S9;\n  *  21.1 version 21.1R1 and later versions;\n  *  21.2 versions prior to 21.2R3-S6;\n  *  21.3 versions prior to 21.3R3-S5;\n  *  21.4 versions prior to 21.4R3-S5;\n  *  22.1 versions prior to 22.1R3-S4;\n  *  22.2 versions prior to 22.2R3-S2;\n  *  22.3 versions prior to 22.3R2-S2, 22.3R3;\n  *  22.4 versions prior to 22.4R2-S1, 22.4R3;\n\n\n\n\n\n\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-168",
                  "description": " CWE-168: Improper Handling of Inconsistent Special Elements",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-12T22:58:49.192Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.juniper.net/JSA73174"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S2, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3, 23.1R2, 23.2R1, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S2, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3, 23.1R2, 23.2R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "advisory": "JSA73174",
            "defect": [
              "1696110"
            ],
            "discovery": "INTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-10-11T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS: SRX Series: The PFE will crash on receiving malformed SSL traffic when Sky ATP is enabled",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eRemoving the security-metadata-streaming policy from the configuration stops the issue.\u003c/p\u003e"
                }
              ],
              "value": "Removing the security-metadata-streaming policy from the configuration stops the issue.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-36843",
        "datePublished": "2023-10-12T22:58:49.192Z",
        "dateReserved": "2023-06-27T16:17:25.276Z",
        "dateUpdated": "2024-09-18T17:53:30.073Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-36841 (GCVE-0-2023-36841)

    Vulnerability from cvelistv5 โ€“ Published: 2023-10-12 22:58 โ€“ Updated: 2024-09-18 18:01
    VLAI
    Title
    Junos OS: MX Series: Receipt of malformed TCP traffic will cause a Denial of Service
    Summary
    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS). An attacker who sends malformed TCP traffic via an interface configured with PPPoE, causes an infinite loop on the respective PFE. This results in consuming all resources and a manual restart is needed to recover. This issue affects interfaces with PPPoE configured and tcp-mss enabled. This issue affects Juniper Networks Junos OS * All versions prior to 20.4R3-S7; * 21.1 version 21.1R1 and later versions; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S3; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3; * 22.3 versions prior to 22.3R2-S2; * 22.4 versions prior to 22.4R2;
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-09-18 17:54 UTC
    CWE
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 0 , < 20.4R3-S7 (semver)
    Affected: 21.1R1 , < 21.1* (semver)
    Affected: 21.2 , < 21.2R3-S6 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3-S3 (semver)
    Affected: 22.1 , < 22.1R3-S4 (semver)
    Affected: 22.2 , < 22.2R3 (semver)
    Affected: 22.3 , < 22.3R2-S2, 22.3R3 (semver)
    Affected: 22.4 , < 22.4R2 (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 20.4r3-s7 (semver)
    Affected: 21.1r1 , < 21.1 (semver)
    Affected: 21.2 , < 21.2r3-s6 (semver)
    Affected: 21.3 , < 21.3r3-s5 (semver)
    Affected: 21.4 , < 21.4r3-s3 (semver)
    Affected: 22.1 , < 22.1r3-s4 (semver)
    Affected: 22.2 , < 22.2r3 (semver)
    Affected: 22.3 , < 22.3r2-s2 (semver)
    Affected: 22.3 , < 22.3r3 (semver)
    Affected: 22.4 , < 22.4r2 (semver)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-10-11 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:01:09.926Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA73172"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4r3-s7",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.1",
                    "status": "affected",
                    "version": "21.1r1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2r3-s6",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3r3-s5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4r3-s3",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1r3-s4",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2r3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r2-s2",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3r3",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.4r2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-36841",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-18T17:54:47.892619Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T18:01:47.921Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "MX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "20.4R3-S7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.1*",
                  "status": "affected",
                  "version": "21.1R1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S6",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S3",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S4",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R2-S2, 22.3R3",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R2",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003ePPPoE can be configured with the following commands:\u003c/p\u003e \u003ctt\u003e[ edit interfaces interface-name ]\u003cbr\u003e\u003c/tt\u003e\u003ctt\u003e [ encapsulation ppp-over-ether; ]\u003c/tt\u003e\u003cp\u003etcp-mss can be enabled with the following command:\u003c/p\u003e \u003ctt\u003e[ tcp-mss mss-value; ]\u003c/tt\u003e"
                }
              ],
              "value": "PPPoE can be configured with the following commands:\n\n [ edit interfaces interface-name ]\n [ encapsulation ppp-over-ether; ]tcp-mss can be enabled with the following command:\n\n [ tcp-mss mss-value; ]"
            }
          ],
          "datePublic": "2023-10-11T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cp\u003eAn Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS).\u003c/p\u003e\u003cp\u003eAn attacker who sends malformed TCP traffic via an interface configured with PPPoE, causes an infinite loop on the respective PFE. This results in consuming all resources and a manual restart is needed to recover.\u003c/p\u003e\u003cp\u003eThis issue affects interfaces with PPPoE configured and tcp-mss enabled.\u003c/p\u003e\u003cp\u003eThis issue affects Juniper Networks Junos OS\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003eAll versions prior to 20.4R3-S7;\u003c/li\u003e\u003cli\u003e21.1 version 21.1R1 and later versions;\u003c/li\u003e\u003cli\u003e21.2 versions prior to 21.2R3-S6;\u003c/li\u003e\u003cli\u003e21.3 versions prior to 21.3R3-S5;\u003c/li\u003e\u003cli\u003e21.4 versions prior to 21.4R3-S3;\u003c/li\u003e\u003cli\u003e22.1 versions prior to 22.1R3-S4;\u003c/li\u003e\u003cli\u003e22.2 versions prior to 22.2R3;\u003c/li\u003e\u003cli\u003e22.3 versions prior to 22.3R2-S2;\u003c/li\u003e\u003cli\u003e22.4 versions prior to 22.4R2;\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e\n\n"
                }
              ],
              "value": "\nAn Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS).\n\nAn attacker who sends malformed TCP traffic via an interface configured with PPPoE, causes an infinite loop on the respective PFE. This results in consuming all resources and a manual restart is needed to recover.\n\nThis issue affects interfaces with PPPoE configured and tcp-mss enabled.\n\nThis issue affects Juniper Networks Junos OS\n\n\n\n  *  All versions prior to 20.4R3-S7;\n  *  21.1 version 21.1R1 and later versions;\n  *  21.2 versions prior to 21.2R3-S6;\n  *  21.3 versions prior to 21.3R3-S5;\n  *  21.4 versions prior to 21.4R3-S3;\n  *  22.1 versions prior to 22.1R3-S4;\n  *  22.2 versions prior to 22.2R3;\n  *  22.3 versions prior to 22.3R2-S2;\n  *  22.4 versions prior to 22.4R2;\n\n\n\n\n\n\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/p\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": " CWE-400: Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-12T22:58:14.922Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportportal.juniper.net/JSA73172"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S7, 21.2R3-S6, 21.4R3-S3, 22.1R3-S4, 22.2R3, 22.3R2-S2, 22.3R3, 22.4R2, 23.2R1, and all subsequent releases.\u003c/p\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S7, 21.2R3-S6, 21.4R3-S3, 22.1R3-S4, 22.2R3, 22.3R2-S2, 22.3R3, 22.4R2, 23.2R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "advisory": "JSA73172",
            "defect": [
              "1707742"
            ],
            "discovery": "USER"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-10-11T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS: MX Series: Receipt of malformed TCP traffic will cause a Denial of Service",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThere are no known workarounds for this issue.\u003c/p\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-av217"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-36841",
        "datePublished": "2023-10-12T22:58:14.922Z",
        "dateReserved": "2023-06-27T16:17:25.276Z",
        "dateUpdated": "2024-09-18T18:01:47.921Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-4481 (GCVE-0-2023-4481)

    Vulnerability from cvelistv5 โ€“ Published: 2023-08-31 23:46 โ€“ Updated: 2024-10-02 15:09
    VLAI
    Title
    Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
    Summary
    An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When certain specific crafted BGP UPDATE messages are received over an established BGP session, one BGP session may be torn down with an UPDATE message error, or the issue may propagate beyond the local system which will remain non-impacted, but may affect one or more remote systems. This issue is exploitable remotely as the crafted UPDATE message can propagate through unaffected systems and intermediate BGP speakers. Continuous receipt of the crafted BGP UPDATE messages will create a sustained Denial of Service (DoS) condition for impacted devices. This issue affects eBGP and iBGP, in both IPv4 and IPv6 implementations. This issue requires a remote attacker to have at least one established BGP session. Improper Input Validation, Denial of Service vulnerability in Juniper Networks, Inc. Junos OS (BGP, rpd modules), Juniper Networks, Inc. Junos OS Evolved (BGP, rpd modules) allows Fuzzing.This issue affectsย  Junos OS:ย  * All versions before 20.4R3-S10, * from 21.1R1 through 21.*, * from 21.2 before 21.2R3-S5, * from 21.3 before 21.3R3-S5, * from 21.4 before 21.4R3-S7 (unaffected from 21.4R3-S5, affected from 21.4R3-S6) * from 22.1 before 22.1R3-S4, * from 22.2 before 22.2R3-S3, * from 22.3 before 22.3R3-S1, * from 22.4 before 22.4R3, * from 23.2 before 23.2R2. Junos OS Evolved: * All versions before 20.4R3-S10-EVO, * from 21.2-EVO before 21.2R3-S7-EVO, * from 21.3-EVO before 21.3R3-S5-EVO, * from 21.4-EVO before 21.4R3-S5-EVO, * from 22.1-EVO before 22.1R3-S4-EVO, * from 22.2-EVO before 22.2R3-S3-EVO, * from 22.3-EVO before 22.3R3-S1-EVO, * from 22.4-EVO before 22.4R3-EVO, * from 23.2-EVO before 23.2R2-EVO.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-10-02 14:52 UTC
    CWE
    • CWE-20 - Improper Input Validation
    • Denial of Service
    References
    Impacted products
    Vendor Product Version
    Juniper Networks, Inc. Junos OS Affected: 0 , < 20.4R3-S10 (semver)
    Affected: 21.2 , < 21.2R3-S5 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3-S7 (semver)
    Affected: 22.1 , < 22.1R3-S4 (semver)
    Affected: 22.2 , < 22.2R3-S3 (se)
    Affected: 22.3 , < 22.3R3-S1 (semver)
    Affected: 22.4 , < 22.4R3 (semver)
    Affected: 23.2 , < 23.2R2 (semver)
    Affected: 21.1R1 , โ‰ค 21.* (semver)
    Create a notification for this product.
    Juniper Networks, Inc. Junos OS Evolved Affected: 0 , < 20.4R3-S10-EVO (semver)
    Affected: 21.2-EVO , < 21.2R3-S7-EVO (semver)
    Affected: 21.3-EVO , < 21.3R3-S5-EVO (semver)
    Affected: 21.4-EVO , < 21.4R3-S5-EVO (semver)
    Affected: 22.1-EVO , < 22.1R3-S4-EVO (semver)
    Affected: 22.2-EVO , < 22.2R3-S3-EVO (semver)
    Affected: 22.3-EVO , < 22.3R3-S1-EVO (semver)
    Affected: 22.4-EVO , < 22.4R3-EVO (semver)
    Affected: 23.2-EVO , < 23.2R2-EVO (semver)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 20.4R3-S10 (semver)
    Affected: 21.2 , < 21.2R3-S5 (semver)
    Affected: 21.3 , < 21.3R3-S5 (semver)
    Affected: 21.4 , < 21.4R3-S7 (semver)
    Affected: 22.1 , < 22.1R3-S4 (semver)
    Affected: 22.2 , < 22.2R3-S3 (semver)
    Affected: 22.3 , < 22.3R3-S1 (semver)
    Affected: 22.4 , < 22.4R3 (semver)
    Affected: 23.2 , < 23.2R2 (semver)
    Affected: 21.1R1 , < 21.* (semver)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    juniper_networks junos_os_evolved Affected: 0 , < 20.4R3-S10-EVO (semver)
    Affected: 21.2-EVO , < 21.2R3-S7-EVO (semver)
    Affected: 21.3-EVO , < 21.3R3-S5-EVO (semver)
    Affected: 21.4-EVO , < 21.4R3-S5-EVO (semver)
    Affected: 22.1-EVO , < 22.1R3-S4-EVO (custom)
    Affected: 22.2-EVO , < 22.2R3-S3-EVO (semver)
    Affected: 22.3-EVO , < 22.3R3-S1-EVO (semver)
    Affected: 22.4-EVO , < 22.4R3-EVO (semver)
    Affected: 23.2-EVO , < 23.2R2-EVO (semver)
        cpe:2.3:a:juniper_networks:junos_os_evolved:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-08-29 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:31:06.348Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://kb.juniper.net/JSA72510"
              },
              {
                "tags": [
                  "technical-description",
                  "x_transferred"
                ],
                "url": "https://www.rfc-editor.org/rfc/rfc7606"
              },
              {
                "tags": [
                  "technical-description",
                  "x_transferred"
                ],
                "url": "https://www.rfc-editor.org/rfc/rfc4271"
              },
              {
                "tags": [
                  "technical-description",
                  "x_transferred"
                ],
                "url": "https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4R3-S10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2R3-S5",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3R3-S5",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4R3-S7",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1R3-S4",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.2R3-S3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3R3-S1",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.4R3",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "23.2R2",
                    "status": "affected",
                    "version": "23.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.*",
                    "status": "affected",
                    "version": "21.1R1",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:juniper_networks:junos_os_evolved:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os_evolved",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.4R3-S10-EVO",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.2R3-S7-EVO",
                    "status": "affected",
                    "version": "21.2-EVO",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.3R3-S5-EVO",
                    "status": "affected",
                    "version": "21.3-EVO",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "21.4R3-S5-EVO",
                    "status": "affected",
                    "version": "21.4-EVO",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.1R3-S4-EVO",
                    "status": "affected",
                    "version": "22.1-EVO",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.2R3-S3-EVO",
                    "status": "affected",
                    "version": "22.2-EVO",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.3R3-S1-EVO",
                    "status": "affected",
                    "version": "22.3-EVO",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "22.4R3-EVO",
                    "status": "affected",
                    "version": "22.4-EVO",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "23.2R2-EVO",
                    "status": "affected",
                    "version": "23.2-EVO",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-4481",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-02T14:52:11.830739Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-02T15:09:38.010Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "BGP",
                "rpd"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks, Inc.",
              "versions": [
                {
                  "lessThan": "20.4R3-S10",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S5",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "semver"
                },
                {
                  "changes": [
                    {
                      "at": "21.4R3-S5",
                      "status": "unaffected"
                    },
                    {
                      "at": "21.4R3-S6",
                      "status": "affected"
                    }
                  ],
                  "lessThan": "21.4R3-S7",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S4",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3-S3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "se"
                },
                {
                  "lessThan": "22.3R3-S1",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R3",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "semver"
                },
                {
                  "lessThan": "23.2R2",
                  "status": "affected",
                  "version": "23.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "21.*",
                  "status": "affected",
                  "version": "21.1R1",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "modules": [
                "BGP",
                "rpd"
              ],
              "product": "Junos OS Evolved",
              "vendor": "Juniper Networks, Inc.",
              "versions": [
                {
                  "lessThan": "20.4R3-S10-EVO",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.2R3-S7-EVO",
                  "status": "affected",
                  "version": "21.2-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.3R3-S5-EVO",
                  "status": "affected",
                  "version": "21.3-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "21.4R3-S5-EVO",
                  "status": "affected",
                  "version": "21.4-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.1R3-S4-EVO",
                  "status": "affected",
                  "version": "22.1-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.2R3-S3-EVO",
                  "status": "affected",
                  "version": "22.2-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.3R3-S1-EVO",
                  "status": "affected",
                  "version": "22.3-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "22.4R3-EVO",
                  "status": "affected",
                  "version": "22.4-EVO",
                  "versionType": "semver"
                },
                {
                  "lessThan": "23.2R2-EVO",
                  "status": "affected",
                  "version": "23.2-EVO",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The following minimal configuration is required:\u003cbr\u003e\u003cbr\u003e\u0026nbsp; [protocols bgp]"
                }
              ],
              "value": "The following minimal configuration is required:\n\n\u00a0 [protocols bgp]"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Ben Cartwright-Cox / bgp.tools"
            }
          ],
          "datePublic": "2023-08-29T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAn Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).\u003c/span\u003e\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eWhen certain specific crafted BGP UPDATE messages are received over an established BGP session, one BGP session may be torn down with an UPDATE message error, or the issue may propagate beyond the local system which will remain non-impacted, but may affect one or more remote systems. This issue is exploitable remotely as the crafted UPDATE message can propagate through unaffected systems and intermediate BGP speakers.\u003c/span\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eContinuous receipt of the crafted BGP UPDATE messages will create a sustained Denial of Service (DoS) condition for impacted devices.\u003c/span\u003e\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eThis issue affects eBGP and iBGP, in both IPv4 and IPv6 implementations.  This issue requires a remote attacker to have at least one established BGP session.\u003c/span\u003e\u003cbr\u003e Improper Input Validation, Denial of Service vulnerability in Juniper Networks, Inc. Junos OS (BGP, rpd modules), Juniper Networks, Inc. Junos OS Evolved (BGP, rpd modules) allows Fuzzing.\u003cp\u003eThis issue affects\u0026nbsp;\u003c/p\u003e\u003cp\u003eJunos OS:\u0026nbsp;\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003eAll versions before 20.4R3-S10,\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003efrom 21.1R1 through 21.*,\u003c/span\u003e\u003c/li\u003e\u003cli\u003efrom 21.2 before 21.2R3-S5,\u003c/li\u003e\u003cli\u003efrom 21.3 before 21.3R3-S5,\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003efrom 21.4 before 21.4R3-S7 (unaffected from 21.4R3-S5, affected from 21.4R3-S6)\u003c/span\u003e\u003c/li\u003e\u003cli\u003efrom 22.1 before 22.1R3-S4,\u003c/li\u003e\u003cli\u003efrom 22.2 before 22.2R3-S3,\u003c/li\u003e\u003cli\u003efrom 22.3 before 22.3R3-S1,\u003c/li\u003e\u003cli\u003efrom 22.4 before 22.4R3,\u003c/li\u003e\u003cli\u003efrom 23.2 before 23.2R2.\u003c/li\u003e\u003c/ul\u003e\u003cspan style=\"background-color: var(--wht);\"\u003eJunos OS Evolved:\u003c/span\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cul\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003eAll versions before 20.4R3-S10-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 21.2-EVO before 21.2R3-S7-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 21.3-EVO before 21.3R3-S5-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 21.4-EVO before 21.4R3-S5-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 22.1-EVO before 22.1R3-S4-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 22.2-EVO before 22.2R3-S3-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 22.3-EVO before 22.3R3-S1-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 22.4-EVO before 22.4R3-EVO,\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan style=\"background-color: var(--wht);\"\u003efrom 23.2-EVO before 23.2R2-EVO.\u003c/span\u003e\u003c/li\u003e\u003c/ul\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).\n\nWhen certain specific crafted BGP UPDATE messages are received over an established BGP session, one BGP session may be torn down with an UPDATE message error, or the issue may propagate beyond the local system which will remain non-impacted, but may affect one or more remote systems. This issue is exploitable remotely as the crafted UPDATE message can propagate through unaffected systems and intermediate BGP speakers.\nContinuous receipt of the crafted BGP UPDATE messages will create a sustained Denial of Service (DoS) condition for impacted devices.\n\nThis issue affects eBGP and iBGP, in both IPv4 and IPv6 implementations.  This issue requires a remote attacker to have at least one established BGP session.\n Improper Input Validation, Denial of Service vulnerability in Juniper Networks, Inc. Junos OS (BGP, rpd modules), Juniper Networks, Inc. Junos OS Evolved (BGP, rpd modules) allows Fuzzing.This issue affects\u00a0\n\nJunos OS:\u00a0\n\n\n\n  *  All versions before 20.4R3-S10,\n  *  from 21.1R1 through 21.*,\n  *  from 21.2 before 21.2R3-S5,\n  *  from 21.3 before 21.3R3-S5,\n  *  from 21.4 before 21.4R3-S7 (unaffected from 21.4R3-S5, affected from 21.4R3-S6)\n  *  from 22.1 before 22.1R3-S4,\n  *  from 22.2 before 22.2R3-S3,\n  *  from 22.3 before 22.3R3-S1,\n  *  from 22.4 before 22.4R3,\n  *  from 23.2 before 23.2R2.\n\n\nJunos OS Evolved:\n\n\n\n  *  All versions before 20.4R3-S10-EVO,\n  *  from 21.2-EVO before 21.2R3-S7-EVO,\n  *  from 21.3-EVO before 21.3R3-S5-EVO,\n  *  from 21.4-EVO before 21.4R3-S5-EVO,\n  *  from 22.1-EVO before 22.1R3-S4-EVO,\n  *  from 22.2-EVO before 22.2R3-S3-EVO,\n  *  from 22.3-EVO before 22.3R3-S1-EVO,\n  *  from 22.4-EVO before 22.4R3-EVO,\n  *  from 23.2-EVO before 23.2R2-EVO."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eJuniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-28",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-28 Fuzzing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-27T17:47:11.855Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://kb.juniper.net/JSA72510"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://www.rfc-editor.org/rfc/rfc7606"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://www.rfc-editor.org/rfc/rfc4271"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.html"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe following software releases have been updated to resolve this specific issue:\u003cbr\u003e\u003c/p\u003e\u003cp\u003eJunos OS: \u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e20.4R3-S10,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.2R3-S7,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.3R3-S5,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.4R3-S5 or \u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.4R3-S7\u003c/span\u003e,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.1R3-S4,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.2R3-S3,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.3R3-S1,\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.4R3,\u003c/span\u003e\u0026nbsp;23.2R2, 23.3R2, 23.4R1, and all subsequent releases\u003cbr\u003e\u003c/p\u003e\u003cp\u003eNote: except for Junos OS 21.4R3-S6 which is affected and unfixed.\u003cbr\u003e\u003c/p\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eJunos OS Evolved: 20.4R3-S10-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.2R3-S7-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.3R3-S5-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e21.4R3-S5-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.1R3-S4-EVO,\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;22.2R3-S3-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.3R3-S1-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e22.4R3-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e23.2R2-EVO,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e23.4R1-EVO,\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"background-color: var(--wht);\"\u003e\u0026nbsp;and all subsequent releases.\u003c/span\u003e\u003c/p\u003e\u003cbr\u003eIt is important that customers implement the workaround in addition to taking any updated software as these crafted UPDATE messages may be propagated to other devices even if non-impacted locally, thereby protecting the network by stopping the propagation of these crafted UPDATE messages.\u003cbr\u003eThe workaround is to configure BGP error tolerance by way of:\u003cbr\u003e\u003cbr\u003e\u0026nbsp; [ protocols bgp bgp-error-tolerance ... ]\u003cbr\u003e\u003cbr\u003eAdditional details can be found at \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.html\"\u003ehttps://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.h...\u003c/a\u003e\u003cbr\u003e\u003cbr\u003eJuniper considers configuring this option to be a Best Common Practice (BCP) as it not only prevents this issue from happening, but protects against similar issues as well.\u003cp\u003e\u003c/p\u003e\u003cp\u003eThis issue is being tracked as PR \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://prsearch.juniper.net/problemreport/PR1709837\"\u003e1709837\u003c/a\u003e\u0026nbsp;which is visible on the Customer Support website.\u003c/p\u003e\u003cp\u003eNote: Juniper SIRT\u0027s \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://kb.juniper.net/KB16765\"\u003epolicy\u003c/a\u003e\u0026nbsp;is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).\u003c/p\u003e\u003cbr\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue:\n\n\nJunos OS: 20.4R3-S10,\u00a021.2R3-S7,\u00a021.3R3-S5,\u00a021.4R3-S5 or 21.4R3-S7,\u00a022.1R3-S4,\u00a022.2R3-S3,\u00a022.3R3-S1,\u00a022.4R3,\u00a023.2R2, 23.3R2, 23.4R1, and all subsequent releases\n\n\nNote: except for Junos OS 21.4R3-S6 which is affected and unfixed.\n\n\n\n\nJunos OS Evolved: 20.4R3-S10-EVO,\u00a021.2R3-S7-EVO,\u00a021.3R3-S5-EVO,\u00a021.4R3-S5-EVO,\u00a022.1R3-S4-EVO,\u00a022.2R3-S3-EVO,\u00a022.3R3-S1-EVO,\u00a022.4R3-EVO,\u00a023.2R2-EVO,\u00a023.4R1-EVO,\u00a0and all subsequent releases.\n\n\nIt is important that customers implement the workaround in addition to taking any updated software as these crafted UPDATE messages may be propagated to other devices even if non-impacted locally, thereby protecting the network by stopping the propagation of these crafted UPDATE messages.\nThe workaround is to configure BGP error tolerance by way of:\n\n\u00a0 [ protocols bgp bgp-error-tolerance ... ]\n\nAdditional details can be found at  https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.h... https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.html \n\nJuniper considers configuring this option to be a Best Common Practice (BCP) as it not only prevents this issue from happening, but protects against similar issues as well.\n\nThis issue is being tracked as PR  1709837 https://prsearch.juniper.net/problemreport/PR1709837 \u00a0which is visible on the Customer Support website.\n\nNote: Juniper SIRT\u0027s  policy https://kb.juniper.net/KB16765 \u00a0is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL)."
            }
          ],
          "source": {
            "advisory": "JSA72510",
            "defect": [
              "1709837"
            ],
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2023-08-29T16:00:00.000Z",
              "value": "Initial Publication"
            }
          ],
          "title": "Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eThe workaround is to configure BGP error tolerance by way of:\u003c/span\u003e\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp; [ protocols bgp bgp-error-tolerance ... ]\u003c/span\u003e\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eAdditional details can be found at \u003c/span\u003e\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.html\"\u003ehttps://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.h...\u003c/a\u003e\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eJuniper considers configuring this option to be a Best Common Practice (BCP) as it not only prevents this issue from happening, but protects against similar issues as well.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "The workaround is to configure BGP error tolerance by way of:\n\n\u00a0 [ protocols bgp bgp-error-tolerance ... ]\n\nAdditional details can be found at  https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.h... https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-error-messages.html \n\nJuniper considers configuring this option to be a Best Common Practice (BCP) as it not only prevents this issue from happening, but protects against similar issues as well."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-4481",
        "datePublished": "2023-08-31T23:46:18.796Z",
        "dateReserved": "2023-08-22T15:37:01.371Z",
        "dateUpdated": "2024-10-02T15:09:38.010Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-36835 (GCVE-0-2023-36835)

    Vulnerability from cvelistv5 โ€“ Published: 2023-07-14 17:11 โ€“ Updated: 2024-11-07 14:24
    VLAI
    Title
    Junos OS: QFX10000 Series: All traffic will be dropped after a specific valid IP packet has been received which needs to be routed over a VXLAN tunnel
    Summary
    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX10000 Series allows a network based attacker to cause a Denial of Service (DoS). If a specific valid IP packet is received and that packet needs to be routed over a VXLAN tunnel, this will result in a PFE wedge condition due to which traffic gets impacted. As this is not a crash and restart scenario, this condition will persist until the system is rebooted to recover. This issue affects Juniper Networks Junos OS on QFX10000: 20.3 version 20.3R1 and later versions; 20.4 versions prior to 20.4R3-S5; 21.1 versions prior to 21.1R3-S5; 21.2 versions prior to 21.2R3-S5; 21.3 versions prior to 21.3R3-S4; 21.4 versions prior to 21.4R3-S1; 22.1 versions prior to 22.1R3; 22.2 versions prior to 22.2R2; 22.3 versions prior to 22.3R1-S2, 22.3R2.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-11-07 14:18 UTC
    CWE
    • CWE-754 - Improper Check for Unusual or Exceptional Conditions
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 20.3 , < 20.3* (custom)
    Affected: 20.4 , < 20.4R3-S5 (custom)
    Affected: 21.1 , < 21.1R3-S5 (custom)
    Affected: 21.2 , < 21.2R3-S5 (custom)
    Affected: 21.3 , < 21.3R3-S4 (custom)
    Affected: 21.4 , < 21.4R3-S1 (custom)
    Affected: 22.1 , < 22.1R3 (custom)
    Affected: 22.2 , < 22.2R2 (custom)
    Affected: 22.3 , < 22.3R1-S2, 22.3R2 (custom)
    Create a notification for this product.
    juniper_networks junos_os Affected: 20.3 , < 20.3* (custom)
    Affected: 20.4 , < 20.4R3-S5 (custom)
    Affected: 21.1 , < 21.1R3-S5 (custom)
    Affected: 21.2 , < 21.2R3-S5 (custom)
    Affected: 21.3 , < 21.3R3-S4 (custom)
    Affected: 21.4 , < 21.4R3-S1 (custom)
    Affected: 22.1 , < 22.1R3 (custom)
    Affected: 22.2 , < 22.2R2 (custom)
    Affected: 22.3 , < 22.3R1-S2 (custom)
    Affected: 22.3 , < 22.3R2 (custom)
        cpe:2.3:a:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-07-12 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:01:09.846Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA71642"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "20.3*",
                    "status": "affected",
                    "version": "20.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.4R3-S5",
                    "status": "affected",
                    "version": "20.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.1R3-S5",
                    "status": "affected",
                    "version": "21.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2R3-S5",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.3R3-S4",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.4R3-S1",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1R3",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.2R2",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R1-S2",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R2",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-36835",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-07T14:18:56.731957Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-07T14:24:52.880Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "QFX10000 Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "20.3R1",
                      "status": "affected"
                    }
                  ],
                  "lessThan": "20.3*",
                  "status": "affected",
                  "version": "20.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "20.4R3-S5",
                  "status": "affected",
                  "version": "20.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.1R3-S5",
                  "status": "affected",
                  "version": "21.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.2R3-S5",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.3R3-S4",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.4R3-S1",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.1R3",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.2R2",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.3R1-S2, 22.3R2",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "To be exposed to this issue the QFX device needs be configured for VXLAN with either of the following statements:\u003cbr\u003e\u003cbr\u003e\u003ctt\u003e\u0026nbsp; [ vlans \u0026lt;vlan\u0026gt; vxlan ]\u003cbr\u003e\u003cbr\u003e\u0026nbsp; [ routing-instances \u0026lt;routing-instance\u0026gt; vxlan ]\u003c/tt\u003e"
                }
              ],
              "value": "To be exposed to this issue the QFX device needs be configured for VXLAN with either of the following statements:\n\n\u00a0 [ vlans \u003cvlan\u003e vxlan ]\n\n\u00a0 [ routing-instances \u003crouting-instance\u003e vxlan ]"
            }
          ],
          "datePublic": "2023-07-12T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX10000 Series allows a network based attacker to cause a Denial of Service (DoS).\u003cbr\u003e\u003cbr\u003eIf a specific valid IP packet is received and that packet needs to be routed over a VXLAN tunnel, this will result in a PFE wedge condition due to which traffic gets impacted. As this is not a crash and restart scenario, this condition will persist until the system is rebooted to recover.\u003cbr\u003e\u003cbr\u003eThis issue affects Juniper Networks Junos OS on QFX10000:\u003cbr\u003e20.3 version 20.3R1 and later versions;\u003cbr\u003e20.4 versions prior to 20.4R3-S5;\u003cbr\u003e21.1 versions prior to 21.1R3-S5;\u003cbr\u003e21.2 versions prior to 21.2R3-S5;\u003cbr\u003e21.3 versions prior to 21.3R3-S4;\u003cbr\u003e21.4 versions prior to 21.4R3-S1;\u003cbr\u003e22.1 versions prior to 22.1R3;\u003cbr\u003e22.2 versions prior to 22.2R2;\u003cbr\u003e22.3 versions prior to 22.3R1-S2, 22.3R2.\u003cbr\u003e"
                }
              ],
              "value": "An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX10000 Series allows a network based attacker to cause a Denial of Service (DoS).\n\nIf a specific valid IP packet is received and that packet needs to be routed over a VXLAN tunnel, this will result in a PFE wedge condition due to which traffic gets impacted. As this is not a crash and restart scenario, this condition will persist until the system is rebooted to recover.\n\nThis issue affects Juniper Networks Junos OS on QFX10000:\n20.3 version 20.3R1 and later versions;\n20.4 versions prior to 20.4R3-S5;\n21.1 versions prior to 21.1R3-S5;\n21.2 versions prior to 21.2R3-S5;\n21.3 versions prior to 21.3R3-S4;\n21.4 versions prior to 21.4R3-S1;\n22.1 versions prior to 22.1R3;\n22.2 versions prior to 22.2R2;\n22.3 versions prior to 22.3R1-S2, 22.3R2.\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003cbr\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-754",
                  "description": "CWE-754 Improper Check for Unusual or Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-07-14T17:11:26.454Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "url": "https://supportportal.juniper.net/JSA71642"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S5, 21.1R3-S5, 21.2R3-S5, 21.3R3-S4, 21.4R3-S1, 22.1R3, 22.2R2, 22.3R1-S2, 22.3R2, 22.4R1, and all subsequent releases.\u003cbr\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S5, 21.1R3-S5, 21.2R3-S5, 21.3R3-S4, 21.4R3-S1, 22.1R3, 22.2R2, 22.3R1-S2, 22.3R2, 22.4R1, and all subsequent releases.\n"
            }
          ],
          "source": {
            "advisory": "JSA71642",
            "defect": [
              "1678992"
            ],
            "discovery": "USER"
          },
          "title": "Junos OS: QFX10000 Series: All traffic will be dropped after a specific valid IP packet has been received which needs to be routed over a VXLAN tunnel",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "There are no known workarounds for this issue.\u003cbr\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-36835",
        "datePublished": "2023-07-14T17:11:26.454Z",
        "dateReserved": "2023-06-27T16:17:25.276Z",
        "dateUpdated": "2024-11-07T14:24:52.880Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-28985 (GCVE-0-2023-28985)

    Vulnerability from cvelistv5 โ€“ Published: 2023-07-14 16:34 โ€“ Updated: 2024-11-07 14:28
    VLAI
    Title
    SRX Series and MX Series: An FPC core is observed when IDP is enabled on the device and a specific malformed SSL packet is received
    Summary
    An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and MX Series allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Continued receipt of this specific packet will cause a sustained Denial of Service condition. On all SRX Series and MX Series platforms, where IDP is enabled and a specific malformed SSL packet is received, the SSL detector crashes leading to an FPC core. This issue affects Juniper Networks SRX Series and MX Series prior to SigPack 3598. In order to identify the current SigPack version, following command can be used: user@junos# show security idp security-package-version
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-11-07 14:25 UTC
    CWE
    • CWE-1286 - Improper Validation of Syntactic Correctness of Input
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: unspecified , < SigPack 3598 (custom)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < SigPack 3598 (custom)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-07-12 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T13:51:39.183Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA71662"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "SigPack 3598",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-28985",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-07T14:25:45.770994Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-07T14:28:11.378Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "SRX Series",
                "MX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "SigPack 3598",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "For this issue to occur, IDP policy has to be enabled on the SRX and MX Series devices to inspect the HTTPS traffic.\u003cbr\u003e\u003cbr\u003e\u003ctt\u003e[ security idp active-policy policy-name ]\u003cbr\u003e[ security idp idp-policy policy-name rulebase-ips rule rule-name ]\u003c/tt\u003e"
                }
              ],
              "value": "For this issue to occur, IDP policy has to be enabled on the SRX and MX Series devices to inspect the HTTPS traffic.\n\n[ security idp active-policy policy-name ]\n[ security idp idp-policy policy-name rulebase-ips rule rule-name ]"
            }
          ],
          "datePublic": "2023-07-12T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and MX Series allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Continued receipt of this specific packet will cause a sustained Denial of Service condition.\u003cbr\u003e\u003cbr\u003eOn all SRX Series and MX Series platforms, where IDP is enabled and a specific malformed SSL packet is received, the SSL detector crashes leading to an FPC core.\u003cbr\u003e\u003cbr\u003eThis issue affects Juniper Networks SRX Series and MX Series prior to SigPack 3598.\u003cbr\u003e\u003cbr\u003eIn order to identify the current SigPack version, following command can be used:\u003cbr\u003e\u003cbr\u003e\u003ctt\u003euser@junos# show security idp security-package-version\u003c/tt\u003e"
                }
              ],
              "value": "An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and MX Series allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Continued receipt of this specific packet will cause a sustained Denial of Service condition.\n\nOn all SRX Series and MX Series platforms, where IDP is enabled and a specific malformed SSL packet is received, the SSL detector crashes leading to an FPC core.\n\nThis issue affects Juniper Networks SRX Series and MX Series prior to SigPack 3598.\n\nIn order to identify the current SigPack version, following command can be used:\n\nuser@junos# show security idp security-package-version"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003cbr\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1286",
                  "description": "CWE-1286 Improper Validation of Syntactic Correctness of Input",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-07-14T16:34:24.993Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "url": "https://supportportal.juniper.net/JSA71662"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The following software releases have been updated to resolve this specific issue: SigPack 3598, and all subsequent releases.\u003cbr\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: SigPack 3598, and all subsequent releases.\n"
            }
          ],
          "source": {
            "advisory": "JSA71662",
            "defect": [
              "1655071"
            ],
            "discovery": "USER"
          },
          "title": "SRX Series and MX Series: An FPC core is observed when IDP is enabled on the device and a specific malformed SSL packet is received",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "There are no known workarounds for this issue.\u003cbr\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-28985",
        "datePublished": "2023-07-14T16:34:24.993Z",
        "dateReserved": "2023-03-29T08:44:10.679Z",
        "dateUpdated": "2024-11-07T14:28:11.378Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-36832 (GCVE-0-2023-36832)

    Vulnerability from cvelistv5 โ€“ Published: 2023-07-14 15:56 โ€“ Updated: 2024-11-07 14:37
    VLAI
    Title
    Junos OS: MX Series: PFE crash upon receipt of specific packet destined to an AMS interface
    Summary
    An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) interface on the device, causing the packet forwarding engine (PFE) to crash, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue is only triggered by packets destined to a local-interface via a service-interface (AMS). AMS is only supported on the MS-MPC, MS-MIC, and MX-SPC3 cards. This issue is not experienced on other types of interfaces or configurations. Additionally, transit traffic does not trigger this issue. This issue affects Juniper Networks Junos OS on MX Series: All versions prior to 19.1R3-S10; 19.2 versions prior to 19.2R3-S7; 19.3 versions prior to 19.3R3-S8; 19.4 versions prior to 19.4R3-S12; 20.2 versions prior to 20.2R3-S8; 20.4 versions prior to 20.4R3-S7; 21.1 versions prior to 21.1R3-S5; 21.2 versions prior to 21.2R3-S5; 21.3 versions prior to 21.3R3-S4; 21.4 versions prior to 21.4R3-S3; 22.1 versions prior to 22.1R3-S2; 22.2 versions prior to 22.2R3; 22.3 versions prior to 22.3R2-S1, 22.3R3; 22.4 versions prior to 22.4R1-S2, 22.4R2.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-11-07 14:29 UTC
    CWE
    • CWE-755 - Improper Handling of Exceptional Conditions
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: unspecified , < 19.1R3-S10 (custom)
    Affected: 19.2 , < 19.2R3-S7 (custom)
    Affected: 19.3 , < 19.3R3-S8 (custom)
    Affected: 19.4 , < 19.4R3-S12 (custom)
    Affected: 20.2 , < 20.2R3-S8 (custom)
    Affected: 20.4 , < 20.4R3-S7 (custom)
    Affected: 21.1 , < 21.1R3-S5 (custom)
    Affected: 21.2 , < 21.2R3-S5 (custom)
    Affected: 21.3 , < 21.3R3-S4 (custom)
    Affected: 21.4 , < 21.4R3-S3 (custom)
    Affected: 22.1 , < 22.1R3-S2 (custom)
    Affected: 22.2 , < 22.2R3 (custom)
    Affected: 22.3 , < 22.3R2-S1, 22.3R3 (custom)
    Affected: 22.4 , < 22.4R1-S2, 22.4R2 (custom)
    Create a notification for this product.
    juniper_networks junos_os Affected: 0 , < 19.1R3-S10 (custom)
    Affected: 19.2 , < 19.2R3-S7 (custom)
    Affected: 19.3 , < 19.3R3-S8 (custom)
    Affected: 19.4 , < 19.4R3-S12 (custom)
    Affected: 20.2 , < 20.2R3-S8 (custom)
    Affected: 20.4 , < 20.4R3-S7 (custom)
    Affected: 21.1 , < 21.1R3-S5 (custom)
    Affected: 21.2 , < 21.2R3-S5 (custom)
    Affected: 21.3 , < 22.3R2-S1 (custom)
    Affected: 21.4 , < 21.4R3-S3 (custom)
    Affected: 22.1 , < 22.1R3-S2 (custom)
    Affected: 22.2 , < 22.2R3 (custom)
    Affected: 22.3 , < 22.3R2-S1 (custom)
    Affected: 22.3 , < 22.3R3 (custom)
    Affected: 22.4 , < 22.4R1-S2 (custom)
    Affected: 22.4 , < 22.4R2 (custom)
        cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-07-12 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:01:09.608Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA71639"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "19.1R3-S10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "19.2R3-S7",
                    "status": "affected",
                    "version": "19.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "19.3R3-S8",
                    "status": "affected",
                    "version": "19.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "19.4R3-S12",
                    "status": "affected",
                    "version": "19.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.2R3-S8",
                    "status": "affected",
                    "version": "20.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "20.4R3-S7",
                    "status": "affected",
                    "version": "20.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.1R3-S5",
                    "status": "affected",
                    "version": "21.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.2R3-S5",
                    "status": "affected",
                    "version": "21.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R2-S1",
                    "status": "affected",
                    "version": "21.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "21.4R3-S3",
                    "status": "affected",
                    "version": "21.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.1R3-S2",
                    "status": "affected",
                    "version": "22.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.2R3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R2-S1",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R3",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4R1-S2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4R2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-36832",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-07T14:29:02.801765Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-07T14:37:52.265Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "MX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "19.1R3-S10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "19.2R3-S7",
                  "status": "affected",
                  "version": "19.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "19.3R3-S8",
                  "status": "affected",
                  "version": "19.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "19.4R3-S12",
                  "status": "affected",
                  "version": "19.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "20.2R3-S8",
                  "status": "affected",
                  "version": "20.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "20.4R3-S7",
                  "status": "affected",
                  "version": "20.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.1R3-S5",
                  "status": "affected",
                  "version": "21.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.2R3-S5",
                  "status": "affected",
                  "version": "21.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.3R3-S4",
                  "status": "affected",
                  "version": "21.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "21.4R3-S3",
                  "status": "affected",
                  "version": "21.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.1R3-S2",
                  "status": "affected",
                  "version": "22.1",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.2R3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.3R2-S1, 22.3R3",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.4R1-S2, 22.4R2",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A sample next-hop-service interface configuration is shown below:\u003cbr\u003e\u003cbr\u003e\u003ctt\u003e\u003cb\u003e\u0026nbsp; set services service-set 3 next-hop-service inside-service-interface ams0.1\u003c/b\u003e\u003cbr\u003e\u003cb\u003e\u0026nbsp; set services service-set 3 next-hop-service outside-service-interface ams0.2\u003c/b\u003e\u003cbr\u003e\u0026nbsp; set services nat rule 1 match-direction input\u003cbr\u003e\u0026nbsp; set services nat rule 1 term 1 from source-address 10.10.10.0/24\u003cbr\u003e\u0026nbsp; set services nat rule 1 term 1 then translated source-pool 1\u003cbr\u003e\u003cb\u003e\u0026nbsp; set services nat rule 1 term 1 then translated translation-type napt-44\u003c/b\u003e\u003cbr\u003e\u0026nbsp; set services nat rule 1 term 1 then translated mapping-type endpoint-independent\u003cbr\u003e\u003cbr\u003e\u0026nbsp; set interfaces ams0 load-balancing-options member-interface mams-0/2/0\u003cbr\u003e\u003cbr\u003e\u003cb\u003e\u0026nbsp; set routing-instances 2 routing-options static route 0.0.0.0/0 next-hop ams0.1\u003c/b\u003e\u003cbr\u003e\u0026nbsp; set routing-instances 2 instance-type virtual-router\u003cbr\u003e\u0026nbsp; set routing-instances 2 interface xe-0/0/0.0\u003cbr\u003e\u0026nbsp; set routing-instances 2 interface ams0.1\u003c/tt\u003e\u003cbr\u003e"
                }
              ],
              "value": "A sample next-hop-service interface configuration is shown below:\n\n\u00a0 set services service-set 3 next-hop-service inside-service-interface ams0.1\n\u00a0 set services service-set 3 next-hop-service outside-service-interface ams0.2\n\u00a0 set services nat rule 1 match-direction input\n\u00a0 set services nat rule 1 term 1 from source-address 10.10.10.0/24\n\u00a0 set services nat rule 1 term 1 then translated source-pool 1\n\u00a0 set services nat rule 1 term 1 then translated translation-type napt-44\n\u00a0 set services nat rule 1 term 1 then translated mapping-type endpoint-independent\n\n\u00a0 set interfaces ams0 load-balancing-options member-interface mams-0/2/0\n\n\u00a0 set routing-instances 2 routing-options static route 0.0.0.0/0 next-hop ams0.1\n\u00a0 set routing-instances 2 instance-type virtual-router\n\u00a0 set routing-instances 2 interface xe-0/0/0.0\n\u00a0 set routing-instances 2 interface ams0.1\n"
            }
          ],
          "datePublic": "2023-07-12T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) interface on the device, causing the packet forwarding engine (PFE) to crash, resulting in a Denial of Service (DoS).  Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.\u003cbr\u003e\u003cbr\u003eThis issue is only triggered by packets destined to a local-interface via a service-interface (AMS).  AMS is only supported on the MS-MPC, MS-MIC, and MX-SPC3 cards.  This issue is not experienced on other types of interfaces or configurations.  Additionally, transit traffic does not trigger this issue.\u003cbr\u003e\u003cbr\u003eThis issue affects Juniper Networks Junos OS on MX Series:\u003cbr\u003eAll versions prior to 19.1R3-S10;\u003cbr\u003e19.2 versions prior to 19.2R3-S7;\u003cbr\u003e19.3 versions prior to 19.3R3-S8;\u003cbr\u003e19.4 versions prior to 19.4R3-S12;\u003cbr\u003e20.2 versions prior to 20.2R3-S8;\u003cbr\u003e20.4 versions prior to 20.4R3-S7;\u003cbr\u003e21.1 versions prior to 21.1R3-S5;\u003cbr\u003e21.2 versions prior to 21.2R3-S5;\u003cbr\u003e21.3 versions prior to 21.3R3-S4;\u003cbr\u003e21.4 versions prior to 21.4R3-S3;\u003cbr\u003e22.1 versions prior to 22.1R3-S2;\u003cbr\u003e22.2 versions prior to 22.2R3;\u003cbr\u003e22.3 versions prior to 22.3R2-S1, 22.3R3;\u003cbr\u003e22.4 versions prior to 22.4R1-S2, 22.4R2.\u003cbr\u003e"
                }
              ],
              "value": "An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) interface on the device, causing the packet forwarding engine (PFE) to crash, resulting in a Denial of Service (DoS).  Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.\n\nThis issue is only triggered by packets destined to a local-interface via a service-interface (AMS).  AMS is only supported on the MS-MPC, MS-MIC, and MX-SPC3 cards.  This issue is not experienced on other types of interfaces or configurations.  Additionally, transit traffic does not trigger this issue.\n\nThis issue affects Juniper Networks Junos OS on MX Series:\nAll versions prior to 19.1R3-S10;\n19.2 versions prior to 19.2R3-S7;\n19.3 versions prior to 19.3R3-S8;\n19.4 versions prior to 19.4R3-S12;\n20.2 versions prior to 20.2R3-S8;\n20.4 versions prior to 20.4R3-S7;\n21.1 versions prior to 21.1R3-S5;\n21.2 versions prior to 21.2R3-S5;\n21.3 versions prior to 21.3R3-S4;\n21.4 versions prior to 21.4R3-S3;\n22.1 versions prior to 22.1R3-S2;\n22.2 versions prior to 22.2R3;\n22.3 versions prior to 22.3R2-S1, 22.3R3;\n22.4 versions prior to 22.4R1-S2, 22.4R2.\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003cbr\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-755",
                  "description": "CWE-755 Improper Handling of Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-07-14T15:56:44.005Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "url": "https://supportportal.juniper.net/JSA71639"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The following software releases have been updated to resolve this specific issue: 19.1R3-S10, 19.2R3-S7, 19.3R3-S8, 19.4R3-S12, 20.2R3-S8, 20.4R3-S7, 21.1R3-S5, 21.2R3-S5, 21.3R3-S4, 21.4R3-S3, 22.1R3-S2, 22.2R3, 22.3R2-S1, 22.3R3, 22.4R1-S2, 22.4R2, 23.1R1, and all subsequent releases.\u003cbr\u003e\u003cbr\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: 19.1R3-S10, 19.2R3-S7, 19.3R3-S8, 19.4R3-S12, 20.2R3-S8, 20.4R3-S7, 21.1R3-S5, 21.2R3-S5, 21.3R3-S4, 21.4R3-S3, 22.1R3-S2, 22.2R3, 22.3R2-S1, 22.3R3, 22.4R1-S2, 22.4R2, 23.1R1, and all subsequent releases.\n\n"
            }
          ],
          "source": {
            "defect": [
              "1707140"
            ],
            "discovery": "USER"
          },
          "title": "Junos OS: MX Series: PFE crash upon receipt of specific packet destined to an AMS interface",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Modify the configuration to not have local/host bound ICMP traffic processed by Service Card (MS-MPC/SPC3) or add protect-RE filter to discard ICMP packets.\u003cbr\u003e"
                }
              ],
              "value": "Modify the configuration to not have local/host bound ICMP traffic processed by Service Card (MS-MPC/SPC3) or add protect-RE filter to discard ICMP packets.\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-36832",
        "datePublished": "2023-07-14T15:56:44.005Z",
        "dateReserved": "2023-06-27T16:17:25.275Z",
        "dateUpdated": "2024-11-07T14:37:52.265Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-36831 (GCVE-0-2023-36831)

    Vulnerability from cvelistv5 โ€“ Published: 2023-07-14 14:56 โ€“ Updated: 2024-11-07 14:41
    VLAI
    Title
    Junos OS: SRX Series: jbuf memory leak when SSL Proxy and UTM Web-Filtering is applied
    Summary
    An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading to a Denial of Service (DoS) condition. Service restoration is only possible by rebooting the system. The jbuf memory leak only occurs in SSL Proxy and UTM Web-Filtering configurations. Other products, platforms, and configurations are not affected by this vulnerability. This issue affects Juniper Networks Junos OS on SRX Series: 22.2 versions prior to 22.2R3; 22.3 versions prior to 22.3R2-S1, 22.3R3; 22.4 versions prior to 22.4R1-S2, 22.4R2. This issue does not affect Juniper Networks Junos OS versions prior to 22.2R2.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-11-07 14:39 UTC
    CWE
    • CWE-703 - Improper Check or Handling of Exceptional Conditions
    • Denial of Service (DoS)
    References
    Impacted products
    Vendor Product Version
    Juniper Networks Junos OS Affected: 22.2 , < 22.2R3 (custom)
    Affected: 22.3 , < 22.3R2-S1, 22.3R3 (custom)
    Affected: 22.4 , < 22.4R1-S2, 22.4R2 (custom)
    Unaffected: unspecified , < 22.2R2 (custom)
    Create a notification for this product.
    juniper_networks junos_os Affected: 22.2 , < 22.2R3 (custom)
    Affected: 22.3 , < 22.3R2-S1 (custom)
    Affected: 22.3 , < 22.3R3 (custom)
    Affected: 22.4 , < 22.4R1-S2 (custom)
    Affected: 22.4 , < 22.4R2 (custom)
    Affected: 0 , < 22.2R2 (custom)
        cpe:2.3:a:juniper_networks:junos_os:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2023-07-12 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T17:01:09.920Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://supportportal.juniper.net/JSA71636"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:juniper_networks:junos_os:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "junos_os",
                "vendor": "juniper_networks",
                "versions": [
                  {
                    "lessThan": "22.2R3",
                    "status": "affected",
                    "version": "22.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R2-S1",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.3R3",
                    "status": "affected",
                    "version": "22.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4R1-S2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.4R2",
                    "status": "affected",
                    "version": "22.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "22.2R2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-36831",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-07T14:39:03.046485Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-07T14:41:49.644Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "SRX Series"
              ],
              "product": "Junos OS",
              "vendor": "Juniper Networks",
              "versions": [
                {
                  "lessThan": "22.2R3",
                  "status": "affected",
                  "version": "22.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.3R2-S1, 22.3R3",
                  "status": "affected",
                  "version": "22.3",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.4R1-S2, 22.4R2",
                  "status": "affected",
                  "version": "22.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "22.2R2",
                  "status": "unaffected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The following sample configuration options highlight the features required to be affected by this issue:\u003cbr\u003e\u003ctt\u003e\u0026nbsp; set services ssl proxy profile SSL-PROXY protocol-version tls12-and-lower\u003cbr\u003e\u0026nbsp; set services ssl proxy profile SSL-PROXY trusted-ca all\u003cbr\u003e\u0026nbsp; set services ssl proxy profile SSL-PROXY root-ca ssl-proxy-ecdsa1\u003cbr\u003e\u0026nbsp; set security pki ca-profile SECURITY-CA-GROUP_1 ca-identity SECURITY-CA-GROUP_1\u003cbr\u003e\u003c/tt\u003e...\u003cbr\u003e\u003ctt\u003e\u0026nbsp; set security utm default-configuration web-filtering juniper-enhanced default log-and-permit\u003cbr\u003e\u0026nbsp; set security utm feature-profile web-filtering juniper-enhanced profile 2 category ... action block\u003cbr\u003e\u003c/tt\u003e...\u003cbr\u003e\u003ctt\u003e\u0026nbsp; set security utm utm-policy 1 web-filtering http-profile 2\u003cbr\u003e\u003c/tt\u003e...\u003cbr\u003e\u003ctt\u003e\u0026nbsp; set security policies from-zone private to-zone internet policy 1 then permit application-services ssl-proxy profile-name SSL-PROXY\u003cbr\u003e\u0026nbsp; set security policies from-zone private to-zone internet policy 1 then permit application-services utm-policy 1\u003c/tt\u003e\u003cbr\u003e"
                }
              ],
              "value": "The following sample configuration options highlight the features required to be affected by this issue:\n\u00a0 set services ssl proxy profile SSL-PROXY protocol-version tls12-and-lower\n\u00a0 set services ssl proxy profile SSL-PROXY trusted-ca all\n\u00a0 set services ssl proxy profile SSL-PROXY root-ca ssl-proxy-ecdsa1\n\u00a0 set security pki ca-profile SECURITY-CA-GROUP_1 ca-identity SECURITY-CA-GROUP_1\n...\n\u00a0 set security utm default-configuration web-filtering juniper-enhanced default log-and-permit\n\u00a0 set security utm feature-profile web-filtering juniper-enhanced profile 2 category ... action block\n...\n\u00a0 set security utm utm-policy 1 web-filtering http-profile 2\n...\n\u00a0 set security policies from-zone private to-zone internet policy 1 then permit application-services ssl-proxy profile-name SSL-PROXY\n\u00a0 set security policies from-zone private to-zone internet policy 1 then permit application-services utm-policy 1\n"
            }
          ],
          "datePublic": "2023-07-12T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading to a Denial of Service (DoS) condition.  Service restoration is only possible by rebooting the system.\u003cbr\u003e\u003cbr\u003eThe jbuf memory leak only occurs in SSL Proxy and UTM Web-Filtering configurations.  Other products, platforms, and configurations are not affected by this vulnerability.\u003cbr\u003e\u003cbr\u003eThis issue affects Juniper Networks Junos OS on SRX Series:\u003cbr\u003e22.2 versions prior to 22.2R3;\u003cbr\u003e22.3 versions prior to 22.3R2-S1, 22.3R3;\u003cbr\u003e22.4 versions prior to 22.4R1-S2, 22.4R2.\u003cbr\u003e\u003cbr\u003eThis issue does not affect Juniper Networks Junos OS versions prior to 22.2R2.\u003cbr\u003e"
                }
              ],
              "value": "An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading to a Denial of Service (DoS) condition.  Service restoration is only possible by rebooting the system.\n\nThe jbuf memory leak only occurs in SSL Proxy and UTM Web-Filtering configurations.  Other products, platforms, and configurations are not affected by this vulnerability.\n\nThis issue affects Juniper Networks Junos OS on SRX Series:\n22.2 versions prior to 22.2R3;\n22.3 versions prior to 22.3R2-S1, 22.3R3;\n22.4 versions prior to 22.4R1-S2, 22.4R2.\n\nThis issue does not affect Juniper Networks Junos OS versions prior to 22.2R2.\n"
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\u003cbr\u003e"
                }
              ],
              "value": "Juniper SIRT is not aware of any malicious exploitation of this vulnerability.\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-703",
                  "description": "CWE-703 Improper Check or Handling of Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "Denial of Service (DoS)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-07-14T14:56:32.306Z",
            "orgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
            "shortName": "juniper"
          },
          "references": [
            {
              "url": "https://supportportal.juniper.net/JSA71636"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The following software releases have been updated to resolve this specific issue: Junos OS 22.2R3, 22.3R2-S1, 22.3R3, 22.4R1-S2, 22.4R2, 23.1R1, and all subsequent releases.\u003cbr\u003e"
                }
              ],
              "value": "The following software releases have been updated to resolve this specific issue: Junos OS 22.2R3, 22.3R2-S1, 22.3R3, 22.4R1-S2, 22.4R2, 23.1R1, and all subsequent releases.\n"
            }
          ],
          "source": {
            "defect": [
              "1709031"
            ],
            "discovery": "USER"
          },
          "title": "Junos OS: SRX Series: jbuf memory leak when SSL Proxy and UTM Web-Filtering is applied",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "There are no known workarounds for this issue.\u003cbr\u003e"
                }
              ],
              "value": "There are no known workarounds for this issue.\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8cbe9d5a-a066-4c94-8978-4b15efeae968",
        "assignerShortName": "juniper",
        "cveId": "CVE-2023-36831",
        "datePublished": "2023-07-14T14:56:32.306Z",
        "dateReserved": "2023-06-27T16:17:25.275Z",
        "dateUpdated": "2024-11-07T14:41:49.644Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }