QID 44124
Date Published: 2023-11-15
QID 44124: Juniper Network Operating System (Junos OS) OS CPU Denial of Service (DoS) (JSA73147)
An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the management daemon (mgd) process of Juniper Networks Junos OS and Junos OS Evolved allows a network-based authenticated low-privileged attacker, by executing a specific command via NETCONF, to cause a CPU Denial of Service to the device's control plane.
This issue affects:
Juniper Networks Junos OS
All versions prior to 20.4R3-S7;
21.2 versions prior to 21.2R3-S5;
21.3 versions prior to 21.3R3-S5;
21.4 versions prior to 21.4R3-S4;
22.1 versions prior to 22.1R3-S2;
22.2 versions prior to 22.2R3;
22.3 versions prior to 22.3R2-S1, 22.3R3;
22.4 versions prior to 22.4R1-S2, 22.4R2.
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.
The low-privileged attacker may cause a CPU Denial of Service to the device's control plane.
- JSA73147 -
supportportal.juniper.net/JSA73147
CVEs related to QID 44124
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA73147 |
|