QID 44123

QID 44123: Juniper Network Operating System (Junos OS Evolved) Not Destined Router Packets Can Reach the Routing-Engine (JSA73162)

Juniper Junos is the network operating system used in Juniper Networks hardware systems.

Due to an improper check for unusual or exceptional conditions in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on PTX10003 series, when specific transit MPLS (Multiprotocol Label Switching) packets are received by the PFE, these packets are internally forwarded to the RE (Routing-Engine).

This issue affects Juniper Networks Junos OS Evolved: all versions prior to 20.4R3-S8-EVO; 21.1-EVO version 21.1R1-EVO and later; 21.2-EVO versions prior to 21.2R3-S6-EVO; 21.3-EVO version 21.3R1-EVO and later; 21.4-EVO versions prior to 21.4R3-S3-EVO; 22.1-EVO versions prior to 22.1R3-S4-EVO; 22.2-EVO versions prior to 22.2R3-S3-EVO; 22.3-EVO versions prior to 22.3R2-S2-EVO, 22.3R3-EVO; 22.4-EVO versions prior to 22.4R2-EVO.

Successful exploitation of this vulnerability allows an unauthenticated adjacent attacker to cause an impact to the integrity of the system.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.1 severity.
  • Solution
    Vendor has released patch addressing the vulnerabilities, for more information please refer JSA73162

    CVEs related to QID 44123

    Software Advisories
    Advisory ID Software Component Link
    JSA73162 URL Logo supportportal.juniper.net/s/article/2023-10-Security-Bulletin-Junos-OS-Evolved-PTX10003-Series-Packets-which-are-not-destined-to-the-router-can-reach-the-RE-CVE-2023-44196?language=en_US