QID 44115

Date Published: 2024-02-21

QID 44115: Juniper Network Operating System (Junos OS) The RPD crash Leads to The Denial of Service (DoS) (JSA73141)

Juniper Junos is the network operating system used in Juniper Networks hardware systems.

Juniper Networks Junos OS Evolved on PTX10003 Series allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream network.

This issue affects Juniper Networks Junos OS Evolved on PTX10003 Series:
All versions prior to 21.4R3-S4-EVO;
22.1 versions prior to 22.1R3-S3-EVO;
22.2 version 22.2R1-EVO and later versions;
22.3 versions prior to 22.3R2-S2-EVO, 22.3R3-S1-EVO;
22.4 versions prior to 22.4R2-S1-EVO, 22.4R3-EVO;
23.2 versions prior to 23.2R2-EVO.

QID detection logic: (Authenticated)

It checks for vulnerable Junos OS version.

Successful exploitation of the vulnerability may result in the router will start forward traffic if a valid route is present in the forwarding table, causing a loop and congestion in the downstream layer-2 domain connected to the device

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Vendor has released patch addressing the vulnerabilities, for more information please refer JSA73153

    Vendor References

    CVEs related to QID 44115

    Software Advisories
    Advisory ID Software Component Link
    JSA73153 URL Logo supportportal.juniper.net/JSA73153