QID 44130

Date Published: 2023-12-18

QID 44130: Juniper Network Operating System (Junos OS) Denial of Service (DoS) Vulnerability (JSA73165)

Juniper Junos is the network operating system used in Juniper Networks hardware systems.

An improper check for unusual or exceptional conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with Precision Time Protocol (PTP) configured can lead to an FPC (Flexible PIC Concentrators) crash and restart.

This issue affects Juniper Networks Junos OS: all versions prior to 20.4R3-S4; 21.1 version 21.1R1 and later versions; 21.2 versions prior to 21.2R3-S2; 21.3 versions prior to 21.3R3-S5; 21.4 versions prior to 21.4R3; 22.1 versions prior to 22.1R3; 22.2 versions prior to 22.2R1-S1, 22.2R2.

Successful exploitation of this vulnerability allows an unauthenticated attacker to cause a Denial of Service (DoS).

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Vendor has released patch addressing the vulnerabilities, for more information please refer JSA73165

    CVEs related to QID 44130

    Software Advisories
    Advisory ID Software Component Link
    JSA73165 URL Logo supportportal.juniper.net/s/article/2023-10-Security-Bulletin-Junos-OS-MX-Series-In-a-PTP-scenario-a-prolonged-routing-protocol-churn-can-trigger-an-FPC-reboot-CVE-2023-44199?language=en_US