QID 43973

Date Published: 2023-02-02

QID 43973: Juniper Network Operating System (Junos OS) Denial of Service (DoS) Vulnerability (JSA70211)

Juniper Junos is the network operating system used in Juniper Networks hardware systems.

A Buffer Overflow vulnerability in SIP ALG of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).

Affected Junos versions:
All versions prior to 19.4R3-S10; 20.2 versions prior to 20.2R3-S6; 20.3 versions prior to 20.3R3-S6; 20.4 versions prior to 20.4R3-S5; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S3; 21.3 versions prior to 21.3R3-S3; 21.4 versions prior to 21.4R3; 22.1 versions prior to 22.1R2-S1, 22.1R3; 22.2 versions prior to 22.2R1-S2, 22.2R2. QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.

Successful exploitation allows a network-based, unauthenticated attacker to cause Denial of Service (DoS).

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Please refer JSA70213

    Vendor References

    CVEs related to QID 43973

    Software Advisories
    Advisory ID Software Component Link
    JSA70211 URL Logo kb.juniper.net/JSA70213