CVE-2023-36832
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/07/2023
Last modified:
26/07/2023
Description
An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) interface on the device, causing the packet forwarding engine (PFE) to crash, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.<br />
<br />
This issue is only triggered by packets destined to a local-interface via a service-interface (AMS). AMS is only supported on the MS-MPC, MS-MIC, and MX-SPC3 cards. This issue is not experienced on other types of interfaces or configurations. Additionally, transit traffic does not trigger this issue.<br />
<br />
This issue affects Juniper Networks Junos OS on MX Series:<br />
All versions prior to 19.1R3-S10;<br />
19.2 versions prior to 19.2R3-S7;<br />
19.3 versions prior to 19.3R3-S8;<br />
19.4 versions prior to 19.4R3-S12;<br />
20.2 versions prior to 20.2R3-S8;<br />
20.4 versions prior to 20.4R3-S7;<br />
21.1 versions prior to 21.1R3-S5;<br />
21.2 versions prior to 21.2R3-S5;<br />
21.3 versions prior to 21.3R3-S4;<br />
21.4 versions prior to 21.4R3-S3;<br />
22.1 versions prior to 22.1R3-S2;<br />
22.2 versions prior to 22.2R3;<br />
22.3 versions prior to 22.3R2-S1, 22.3R3;<br />
22.4 versions prior to 22.4R1-S2, 22.4R2.<br />
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | 19.1 (excluding) | |
cpe:2.3:o:juniper:junos:19.1:-:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:19.1:r1:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:19.1:r1-s1:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:19.1:r1-s2:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:19.1:r1-s3:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:19.1:r1-s4:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:19.1:r1-s5:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:19.1:r1-s6:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:19.1:r2:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:19.1:r2-s1:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:19.1:r2-s2:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:19.1:r2-s3:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:19.1:r3:*:*:*:*:*:* | ||
cpe:2.3:o:juniper:junos:19.1:r3-s1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page