QID 44159
Date Published: 2024-01-22
QID 44159: Juniper Network Operating System (Junos OS) Denial of Service (DoS) Vulnerability (JSA75723)
Juniper Junos is the network operating system used in Juniper Networks hardware systems.
An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's control, to flap BGP sessions and cause the routing protocol daemon (rpd) process to crash and restart, leading to a Denial of Service (DoS) condition.
Note: This issue only affects routers configured with non-stop routing (NSR) enabled.
This issue affects all versions of Junos OS:
All versions earlier than 20.4R3-S9
21.2 versions earlier than 21.2R3-S7
21.3 versions earlier than 21.3R3-S5
21.4 versions earlier than 21.4R3-S5
22.1 versions earlier than 22.1R3-S4
22.2 versions earlier than 22.2R3-S3
22.3 versions earlier than 22.3R3-S1
22.4 versions earlier than 22.4R2-S2, 22.4R3
23.2 versions earlier than 23.2R1-S1, 23.2R2
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.
Successful exploitation of this vulnerability by the attacker will create a sustained Denial of Service (DoS) condition.
Workaround:
Long-Lived Graceful Restart (LLGR) helper mode can be disabled to prevent this issue. For example:
[edit protocols bgp graceful-restart]
disable;
- JSA75723 -
supportportal.juniper.net/JSA75723
CVEs related to QID 44159
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA75723 |
|