QID 43975
Date Published: 2023-02-02
QID 43975: Juniper Network Operating System (Junos OS) Denial of Service (DoS) Vulnerability (JSA69898)
Juniper Junos is the network operating system used in Juniper Networks hardware systems.
Due to the Improper Handling of an Unexpected Data Type in the processing of EVPN routes on Juniper Networks Junos OS and Junos OS Evolved, an attacker in direct control of a BGP client connected to a route reflector, or via a machine in the middle (MITM) attack, can send a specific EVPN route contained within a BGP Update, triggering a routing protocol daemon (RPD) crash, leading to a Denial of Service (DoS) condition. Continued receipt and processing of these specific EVPN routes could create a sustained Denial of Service (DoS) condition.
Affected Junos versions:
21.3 versions prior to 21.3R3-S2;
21.4 versions prior to 21.4R2-S2, 21.4R3;
22.1 versions prior to 22.1R1-S2, 22.1R3;
22.2 versions prior to 22.2R2.
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.
Successful exploitation allows a network-based, unauthenticated attacker to cause Denial of Service (DoS).
- JSA69898 -
kb.juniper.net/JSA69898
CVEs related to QID 43975
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA69898 |
|