QID 43958
Date Published: 2023-01-30
QID 43958: Juniper Network Operating System (Junos OS) MX and SRX Series Inconsistent NAT Configuration Vulnerability (JSA70205)
Juniper Junos is the network operating system used in Juniper Networks hardware systems.
Affected releases are Junos OS:
All versions prior to 19.4R3-S10;
20.1 version 20.1R1 and later versions;
20.2 versions prior to 20.2R3-S6;
20.3 versions prior to 20.3R3-S6;
20.4 versions prior to 20.4R3-S5;
21.1 versions prior to 21.1R3-S4;
21.2 versions prior to 21.2R3-S3;
21.3 versions prior to 21.3R3-S3;
21.4 versions prior to 21.4R3-S1;
22.1 versions prior to 22.1R2-S2, 22.1R3;
22.2 versions prior to 22.2R2.
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.
An Unchecked Input for Loop Condition vulnerability in a NAT library of Juniper Networks Junos OS allows a local authenticated attacker with low privileges to cause a Denial of Service (DoS).
For more information please visit JSA70205.
Workaround:
When an inconsistent "deterministic NAT" configuration is present on an SRX, or MX with SPC3 and then a specific CLI command is issued the SPC will crash and restart. Repeated execution of this command will lead to a sustained DoS.
- JSA70205 -
kb.juniper.net/JSA70205
CVEs related to QID 43958
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA70205 |
|