QID 44133

Date Published: 2023-12-18

QID 44133: Juniper Network Operating System (Junos OS) Denial of Service (DoS) Vulnerability (JSA73157)

Juniper Junos is the network operating system used in Juniper Networks hardware systems.

An Improper Release of Memory Before Removing Last Reference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a local, low privileged attacker to cause an FPC crash, leading to Denial of Service (DoS).

This issue affects Juniper Networks Junos OS on MX Series: all versions prior to 20.4R3-S7; 21.1 versions prior to 21.1R3-S5; 21.2 versions prior to 21.2R3-S4; 21.3 versions prior to 21.3R3-S4; 21.4 versions prior to 21.4R3-S3; 22.1 versions prior to 22.1R3-S1; 22.2 versions prior to 22.2R2-S1, 22.2R3; 22.3 versions prior to 22.3R1-S2, 22.3R2.

Successful exploitation of this vulnerability can lead to sustained Denial of Service condition.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.9 severity.
  • Solution
    Vendor has released patch addressing the vulnerabilities, for more information please refer JSA73157

    CVEs related to QID 44133

    Software Advisories
    Advisory ID Software Component Link
    JSA73157 URL Logo supportportal.juniper.net/s/article/2023-10-Security-Bulletin-Junos-OS-MX-Series-An-FPC-crash-is-observed-when-CFM-is-enabled-in-a-VPLS-scenario-and-a-specific-LDP-related-command-is-run-CVE-2023-44193?language=en_US