QID 44074
Date Published: 2023-07-03
QID 44074: Juniper Network Operating System (Junos OS) Denial of Service (DoS) Vulnerability (JSA71542)
Juniper Junos is the network operating system used in Juniper Networks hardware systems.
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).
Affected Juniper Networks Junos OS versions:
15.1R1 and later versions prior to 20.4R3-S8
21.1 version 21.1R1 and later versions prior to 21.2R3-S6
21.3 versions prior to 21.3R3-S5
21.4 versions prior to 21.4R3-S4
22.1 versions prior to 22.1R3-S4
22.2 versions prior to 22.2R3-S2
22.3 versions prior to 22.2R3-S2
22.4 versions prior to 22.4R2-S1, 22.4R3
23.1 versions prior to 23.1R1-S1, 23.1R2
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.
Note: This QID doesn't check for the available workaround, hence marked potential.
Successful exploitation of this vulnerability may allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).
Junos OS: 20.4R3-S8*, 21.2R3-S6*, 21.3R3-S5*, 21.4R3-S4, 22.1R3-S4*, 22.2R3-S2*, 22.3R2-S2*, 22.3R3-S1*, 22.4R2-S1*, 22.4R3*, 23.1R1-S1*, 23.1R2*, 23.2R1*, and all subsequent releases.
Please refer JSA71542 advisory for further information.
Workaround:
The workaround is to configure BGP error tolerance by way of:
[ protocols bgp bgp-error-tolerance ... ]
which causes malformed BGP routes to be 'treated as withdrawal' instead of bringing down the BGP session.
- JSA71542 -
kb.juniper.net/JSA71542
CVEs related to QID 44074
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA71542 |
|