QID 44132
Date Published: 2023-12-18
QID 44132: Juniper Network Operating System (Junos OS) Improper Input Validation Vulnerability (JSA73148)
Juniper Junos is the network operating system used in Juniper Networks hardware systems.
An Improper Input Validation vulnerability in the VxLAN packet forwarding engine (PFE) of Juniper Networks Junos OS on QFX5000 Series, EX4600 Series devices allows an unauthenticated, adjacent attacker, sending two or more genuine packets in the same VxLAN topology.
This issue affects Juniper Networks Junos OS on QFX5000 Series, EX4600 Series: 18.4 version 18.4R2 and later versions prior to 20.4R3-S8; 21.1 version 21.1R1 and later versions prior to 21.2R3-S6; 21.3 versions prior to 21.3R3-S5; 21.4 versions prior to 21.4R3-S4; 22.1 versions prior to 22.1R3-S3; 22.2 versions prior to 22.2R3-S1; 22.3 versions prior to 22.3R2-S2, 22.3R3; 22.4 versions prior to 22.4R2.
Successful exploitation of this vulnerability may cause a DMA memory leak to occur under various specific operational conditions.