QID 44117
Date Published: 2024-02-21
QID 44117: Juniper Network Operating System (Junos OS) The RPD Crash Leading to a Denial of Service (DoS) (JSA73170)
An Improper Validation of Syntactic Correctness of Input vulnerability in Routing Protocol Daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). When a malformed BGP UPDATE packet is received over an established BGP session, the rpd crashes and restarts. This issue requires an attacker to have an established BGP session to a system affected by the issue. This issue affects both eBGP and iBGP implementations.
This issue affects:
Juniper Networks Junos OS
21.4 versions prior to 21.4R3-S4;
22.1 versions prior to 22.1R3-S3;
22.2 versions prior to 22.2R3-S2;
22.3 versions prior to 22.3R2-S2, 22.3R3;
22.4 versions prior to 22.4R2-S1, 22.4R3;
23.2 versions prior to 23.2R1, 23.2R2;
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.
The impact of the RPD crash will cause a Denial of Service (DoS).
- JSA73170 -
supportportal.juniper.net/JSA73170
CVEs related to QID 44117
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA73170 |
|