QID 43968

Date Published: 2023-02-02

QID 43968: Juniper Network Operating System (Junos OS) Denial of Service (DoS) Vulnerability (JSA70212)

Juniper Junos is the network operating system used in Juniper Networks hardware systems.

A Buffer Overflow vulnerability in SIP ALG of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).

Affected Junos versions:
Juniper Networks Junos OS on MX Series and SRX Series 20.4 versions prior to 20.4R3-S5
21.1 versions prior to 21.1R3-S4
21.2 versions prior to 21.2R3-S2
21.3 versions prior to 21.3R3-S1
21.4 versions prior to 21.4R3
22.1 versions prior to 22.1R1-S2, 22.1R2
22.2 versions prior to 22.2R1-S1, 22.2R2
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.

Note: This QID does not checks for only affected versions hence set to practice.

Successful exploitation allows a network-based, unauthenticated attacker to cause Denial of Service (DoS).

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    The following software releases have been updated to resolve this specific issue: 20.4R3-S5,21.1R3-S4,21.2R3-S2,21.3R3-S1,21.4R3, 22.1R1-S2,22.2R1-S1 and all subsequent releases. Please refer JSA70212

    Vendor References

    CVEs related to QID 43968

    Software Advisories
    Advisory ID Software Component Link
    JSA70212 URL Logo kb.juniper.net/JSA70212