QID 43922
Date Published: 2022-10-17
QID 43922: Juniper Network Operating System (Junos OS) Denial of Service (DoS) Vulnerability (JSA11279)
Juniper Junos is the network operating system used in Juniper Networks hardware systems.
A Missing Release of Memory after Effective Lifetime vulnerability in the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause Denial of Service (DoS).
Affected Junos OS versions:
All versions prior to 18.3R3-S6
18.4 versions prior to 18.4R2-S9, 18.4R3-S10
19.1 versions prior to 19.1R2-S3, 19.1R3-S7
19.2 versions prior to 19.2R1-S8, 19.2R3-S4
19.3 versions prior to 19.3R3-S4
19.4 versions prior to 19.4R2-S5, 19.4R3-S5
20.1 versions prior to 20.1R3-S1
20.2 versions prior to 20.2R3-S2
20.3 versions prior to 20.3R3-S1
20.4 versions prior to 20.4R3
21.1 versions prior to 21.1R2, 21.1R3
21.2 versions prior to 21.2R1-S1, 21.2R2
NOTE:
To be affected a system would need to be configured with:
[ security pki ca-profile <ca-profile-name> revocation-check crl url <url-name> ]
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.
Successful exploitation of this vulnerability may allow an attacker to consume all available memory and lead to an inoperable state of the affected system causing a DoS on the target system.
- JSA11279 -
kb.juniper.net/JSA11279
CVEs related to QID 43922
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA11279 |
|