QID 44121
Date Published: 2023-11-27
QID 44121: Juniper Network Operating System (Junos OS) SIP ALG Forwards Specifically Malformed Retransmitted SIP Packets (JSA73164)
Juniper Junos is the network operating system used in Juniper Networks hardware systems.
In Juniper Networks Junos OS on SRX Series and MX Series if the SIP ALG is configured and a device receives a specifically malformed SIP packet, the device prevents this packet from being forwarded, but any subsequently received retransmissions of the same packet are forwarded as if they were valid.
This issue affects Juniper Networks Junos OS on SRX Series and MX Series: 20.4 versions prior to 20.4R3-S5; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S4; 21.3 versions prior to 21.3R3-S3; 21.4 versions prior to 21.4R3-S2; 22.1 versions prior to 22.1R2-S2, 22.1R3; 22.2 versions prior to 22.2R2-S1, 22.2R3; 22.3 versions prior to 22.3R1-S2, 22.3R2. This issue doesn't not affected releases prior to 20.4R1.
Successful exploitation of this vulnerability allows an unauthenticated network-based attacker to cause an integrity impact in connected networks.