QID 43953
Date Published: 2023-01-30
QID 43953: Juniper Network Operating System (Junos OS) Denial of Service (DoS) Vulnerability (JSA70200)
An Out-of-bounds Write vulnerability in the Internet Key Exchange Protocol daemon (iked) of Juniper Networks Junos OS on SRX series and MX with SPC3 allows an authenticated, network-based attacker to cause a Denial of Service (DoS).
Affected Junos versions:
This issue affects Juniper Networks Junos OS on SRX Series, and MX Series with SPC3:
All versions prior to 19.3R3-S7
19.4 versions prior to 19.4R3-S9
20.2 versions prior to 20.2R3-S5
20.3 versions prior to 20.3R3-S5
20.4 versions prior to 20.4R3-S4
21.1 versions prior to 21.1R3-S3
21.2 versions prior to 21.2R3-S2
21.3 versions prior to 21.3R3-S1
21.4 versions prior to 21.4R2-S1, 21.4R3
22.1 versions prior to 22.1R1-S2, 22.1R2
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.
Note that this payload is only processed after the authentication has successfully completed. So the issue can only be exploited by an attacker who can successfully authenticate.
- JSA70200 -
kb.juniper.net/JSA70200
CVEs related to QID 43953
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA70200 |
|