QID 44174
Date Published: 2024-03-05
QID 44174: Juniper Network Operating System (Junos OS) Denial of Service (DoS) Vulnerability (JSA73152)
CVE-2023-44188: A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in telemetry processing of Juniper Networks Junos OS allows a network-based authenticated attacker to flood the system with multiple telemetry requests, causing the Junos Kernel Debugging Streaming Daemon (jkdsd) process to crash, leading to a Denial of Service (DoS).
These issues affect Juniper Networks Junos OS on NFX-Series,EX-Series,QFX-Series,ACXMX-Series,PTX-Series
Affected Juniper Networks Junos OS versions:
20.4 versions prior to 20.4R3-S9;
21.1 versions 21.1R1 and later;
21.2 versions prior to 21.2R3-S6;
21.3 versions prior to 21.3R3-S5;
21.4 versions prior to 21.4R3-S5;
22.1 versions prior to 22.1R3-S4;
22.2 versions prior to 22.2R3-S2;
22.3 versions prior to 22.3R2-S1, 22.3R3-S1;
22.4 versions prior to 22.4R2-S2, 22.4R3;
23.1 versions prior to 23.1R2.
QID detection logic: (Authenticated)
This QID checks for vulnerable Junos OS version.
QID detection logic: (Unauthenticated)
This QID checks SNMP banner for vulnerable version of JunOS.
Successful exploitation may cause the Junos Kernel Debugging Streaming Daemon (jkdsd) process to crash, leading to a Denial of Service (DoS).
CVEs related to QID 44174
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA73152 |
|