QID 43966
Date Published: 2023-03-21
QID 43966: Juniper Network Operating System (Junos OS) MPLS TE Tunnel Configuration Vulnerability (JSA70203)
Juniper Junos is the network operating system used in Juniper Networks hardware systems.
An Incomplete Cleanup vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS).
This issue affects:
All versions prior to 18.4R2-S7;
19.1 versions prior to 19.1R3-S2;
19.2 versions prior to 19.2R3;
19.3 versions prior to 19.3R3;
19.4 versions prior to 19.4R3;
20.1 versions prior to 20.1R2;
20.2 versions prior to 20.2R2.
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.
allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).
For more information please visit JSA70203.
Workaround:
Remove 'protocols rsvp interface link-protection max-bypasses.
- JSA70204 -
kb.juniper.net/JSA70203
CVEs related to QID 43966
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA702043 |
|