QID 44164
Date Published: 2024-01-22
QID 44164: Juniper Network Operating System (Junos OS) Denial of Service (DoS) Vulnerability (JSA75742)
Juniper Junos is the network operating system used in Juniper Networks hardware systems.
A Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) vulnerability in the Flow-processing Daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos).
On SRX Series devices when two different threads try to simultaneously process a queue which is used for TCP events flowd will crash. One of these threads can not be triggered externally, so the exploitation of this race condition is outside the attackers direct control.
Note: This issue does not affect Juniper Networks Junos OS versions earlier than 21.2R1.
Affected Model: srx series
Affected Versions:
21.2 versions earlier than 21.2R3-S5
21.3 versions earlier than 21.3R3-S5
21.4 versions earlier than 21.4R3-S4
22.1 versions earlier than 22.1R3-S3
22.2 versions earlier than 22.2R3-S1
22.3 versions earlier than 22.3R2-S2, 22.3R3
22.4 versions earlier than 22.4R2-S1, 22.4R3
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.
Successful exploitation of this vulnerability by an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos).
- JSA75742 -
supportportal.juniper.net/JSA75742
CVEs related to QID 44164
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA75742 |
|