CVE-2023-36838
Summary
| CVE | CVE-2023-36838 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-14 17:15:00 UTC |
| Updated | 2023-07-27 13:28:00 UTC |
| Description | An Out-of-bounds Read vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a local, authenticated attacker with low privileges, to cause a Denial of Service (DoS). If a low privileged user executes a specific CLI command, flowd which is responsible for traffic forwarding in SRX crashes and generates a core dump. This will cause temporary traffic interruption until the flowd process is restarted automatically. Continued execution of this command will lead to a sustained DoS. This issue affects Juniper Networks Junos OS on SRX Series: All versions prior to 20.2R3-S7; 20.3 version 20.3R1 and later versions; 20.4 versions prior to 20.4R3-S6; 21.1 versions prior to 21.1R3-S5; 21.2 versions prior to 21.2R3-S4; 21.3 versions prior to 21.3R3-S4; 21.4 versions prior to 21.4R3-S3; 22.1 versions prior to 22.1R3-S1; 22.2 versions prior to 22.2R3; 22.3 versions prior to 22.3R2; 22.4 versions prior to 22.4R1-S1, 22.4R2. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Juniper | Csrx | - | All | All | All |
| Operating System | Juniper | Junos | All | All | All | All |
| Operating System | Juniper | Junos | 20.2 | - | All | All |
| Operating System | Juniper | Junos | 20.2 | r1 | All | All |
| Operating System | Juniper | Junos | 20.2 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 20.2 | r1-s2 | All | All |
| Operating System | Juniper | Junos | 20.2 | r1-s3 | All | All |
| Operating System | Juniper | Junos | 20.2 | r2 | All | All |
| Operating System | Juniper | Junos | 20.2 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 20.2 | r2-s2 | All | All |
| Operating System | Juniper | Junos | 20.2 | r2-s3 | All | All |
| Operating System | Juniper | Junos | 20.2 | r3 | All | All |
| Operating System | Juniper | Junos | 20.2 | r3-s1 | All | All |
| Operating System | Juniper | Junos | 20.2 | r3-s2 | All | All |
| Operating System | Juniper | Junos | 20.2 | r3-s3 | All | All |
| Operating System | Juniper | Junos | 20.2 | r3-s4 | All | All |
| Operating System | Juniper | Junos | 20.2 | r3-s5 | All | All |
| Operating System | Juniper | Junos | 20.2 | r3-s6 | All | All |
| Operating System | Juniper | Junos | 20.3 | r1 | All | All |
| Operating System | Juniper | Junos | 20.3 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 20.3 | r1-s2 | All | All |
| Operating System | Juniper | Junos | 20.3 | r2 | All | All |
| Operating System | Juniper | Junos | 20.3 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 20.3 | r3 | All | All |
| Operating System | Juniper | Junos | 20.3 | r3-s1 | All | All |
| Operating System | Juniper | Junos | 20.3 | r3-s2 | All | All |
| Operating System | Juniper | Junos | 20.3 | r3-s3 | All | All |
| Operating System | Juniper | Junos | 20.3 | r3-s4 | All | All |
| Operating System | Juniper | Junos | 20.3 | r3-s5 | All | All |
| Operating System | Juniper | Junos | 20.3 | r3-s6 | All | All |
| Operating System | Juniper | Junos | 20.4 | - | All | All |
| Operating System | Juniper | Junos | 20.4 | r1 | All | All |
| Operating System | Juniper | Junos | 20.4 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 20.4 | r2 | All | All |
| Operating System | Juniper | Junos | 20.4 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 20.4 | r2-s2 | All | All |
| Operating System | Juniper | Junos | 20.4 | r3 | All | All |
| Operating System | Juniper | Junos | 20.4 | r3-s1 | All | All |
| Operating System | Juniper | Junos | 20.4 | r3-s2 | All | All |
| Operating System | Juniper | Junos | 20.4 | r3-s3 | All | All |
| Operating System | Juniper | Junos | 20.4 | r3-s4 | All | All |
| Operating System | Juniper | Junos | 20.4 | r3-s5 | All | All |
| Operating System | Juniper | Junos | 21.1 | - | All | All |
| Operating System | Juniper | Junos | 21.1 | r1 | All | All |
| Operating System | Juniper | Junos | 21.1 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 21.1 | r2 | All | All |
| Operating System | Juniper | Junos | 21.1 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 21.1 | r2-s2 | All | All |
| Operating System | Juniper | Junos | 21.1 | r3 | All | All |
| Operating System | Juniper | Junos | 21.1 | r3-s1 | All | All |
| Operating System | Juniper | Junos | 21.1 | r3-s2 | All | All |
| Operating System | Juniper | Junos | 21.1 | r3-s3 | All | All |
| Operating System | Juniper | Junos | 21.1 | r3-s4 | All | All |
| Operating System | Juniper | Junos | 21.2 | - | All | All |
| Operating System | Juniper | Junos | 21.2 | r1 | All | All |
| Operating System | Juniper | Junos | 21.2 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 21.2 | r1-s2 | All | All |
| Operating System | Juniper | Junos | 21.2 | r2 | All | All |
| Operating System | Juniper | Junos | 21.2 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 21.2 | r2-s2 | All | All |
| Operating System | Juniper | Junos | 21.2 | r3 | All | All |
| Operating System | Juniper | Junos | 21.2 | r3-s1 | All | All |
| Operating System | Juniper | Junos | 21.2 | r3-s2 | All | All |
| Operating System | Juniper | Junos | 21.2 | r3-s3 | All | All |
| Operating System | Juniper | Junos | 21.3 | - | All | All |
| Operating System | Juniper | Junos | 21.3 | r1 | All | All |
| Operating System | Juniper | Junos | 21.3 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 21.3 | r1-s2 | All | All |
| Operating System | Juniper | Junos | 21.3 | r2 | All | All |
| Operating System | Juniper | Junos | 21.3 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 21.3 | r2-s2 | All | All |
| Operating System | Juniper | Junos | 21.3 | r3 | All | All |
| Operating System | Juniper | Junos | 21.3 | r3-s1 | All | All |
| Operating System | Juniper | Junos | 21.3 | r3-s2 | All | All |
| Operating System | Juniper | Junos | 21.3 | r3-s3 | All | All |
| Operating System | Juniper | Junos | 21.4 | - | All | All |
| Operating System | Juniper | Junos | 21.4 | r1 | All | All |
| Operating System | Juniper | Junos | 21.4 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 21.4 | r1-s2 | All | All |
| Operating System | Juniper | Junos | 21.4 | r2 | All | All |
| Operating System | Juniper | Junos | 21.4 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 21.4 | r2-s2 | All | All |
| Operating System | Juniper | Junos | 21.4 | r3 | All | All |
| Operating System | Juniper | Junos | 21.4 | r3-s1 | All | All |
| Operating System | Juniper | Junos | 21.4 | r3-s2 | All | All |
| Operating System | Juniper | Junos | 22.1 | r1 | All | All |
| Operating System | Juniper | Junos | 22.1 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 22.1 | r1-s2 | All | All |
| Operating System | Juniper | Junos | 22.1 | r2 | All | All |
| Operating System | Juniper | Junos | 22.1 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 22.1 | r2-s2 | All | All |
| Operating System | Juniper | Junos | 22.1 | r3 | All | All |
| Operating System | Juniper | Junos | 22.2 | r1 | All | All |
| Operating System | Juniper | Junos | 22.2 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 22.2 | r1-s2 | All | All |
| Operating System | Juniper | Junos | 22.2 | r2 | All | All |
| Operating System | Juniper | Junos | 22.2 | r2-s1 | All | All |
| Operating System | Juniper | Junos | 22.2 | r2-s2 | All | All |
| Operating System | Juniper | Junos | 22.3 | r1 | All | All |
| Operating System | Juniper | Junos | 22.3 | r1-s1 | All | All |
| Operating System | Juniper | Junos | 22.3 | r1-s2 | All | All |
| Operating System | Juniper | Junos | 22.4 | r1 | All | All |
| Hardware | Juniper | Srx100 | - | All | All | All |
| Hardware | Juniper | Srx110 | - | All | All | All |
| Hardware | Juniper | Srx1400 | - | All | All | All |
| Hardware | Juniper | Srx1500 | - | All | All | All |
| Hardware | Juniper | Srx210 | - | All | All | All |
| Hardware | Juniper | Srx220 | - | All | All | All |
| Hardware | Juniper | Srx240 | - | All | All | All |
| Hardware | Juniper | Srx240h2 | - | All | All | All |
| Hardware | Juniper | Srx240m | - | All | All | All |
| Hardware | Juniper | Srx300 | - | All | All | All |
| Hardware | Juniper | Srx320 | - | All | All | All |
| Hardware | Juniper | Srx340 | - | All | All | All |
| Hardware | Juniper | Srx3400 | - | All | All | All |
| Hardware | Juniper | Srx345 | - | All | All | All |
| Hardware | Juniper | Srx3600 | - | All | All | All |
| Hardware | Juniper | Srx380 | - | All | All | All |
| Hardware | Juniper | Srx4000 | - | All | All | All |
| Hardware | Juniper | Srx4100 | - | All | All | All |
| Hardware | Juniper | Srx4200 | - | All | All | All |
| Hardware | Juniper | Srx4600 | - | All | All | All |
| Hardware | Juniper | Srx5000 | - | All | All | All |
| Hardware | Juniper | Srx5400 | - | All | All | All |
| Hardware | Juniper | Srx550 | - | All | All | All |
| Hardware | Juniper | Srx550m | - | All | All | All |
| Hardware | Juniper | Srx550 Hm | - | All | All | All |
| Hardware | Juniper | Srx5600 | - | All | All | All |
| Hardware | Juniper | Srx5800 | - | All | All | All |
| Hardware | Juniper | Srx650 | - | All | All | All |
| Application | Juniper | Vsrx | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CEC Juniper Community | MISC | supportportal.juniper.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.