← Back

CVE-2023-28985

nvd nist
Published: Jul 14, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: sirt@juniper.net (Secondary)

Description

An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and MX Series allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Continued receipt of this specific packet will cause a sustained Denial of Service condition. On all SRX Series and MX Series platforms, where IDP is enabled and a specific malformed SSL packet is received, the SSL detector crashes leading to an FPC core. This issue affects Juniper Networks SRX Series and MX Series prior to SigPack 3598. In order to identify the current SigPack version, following command can be used: user@junos# show security idp security-package-version

Affected (1)

Products: Juniper: Junos
1 product
Junos
Configuration A
1 vulnerable · 47 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Juniper
Csrx
All versions
Juniper
Mx10
All versions
Juniper
Mx10000
All versions
Juniper
Mx10003
All versions
Juniper
Mx10008
All versions
Juniper
Mx10016
All versions
Juniper
Mx104
All versions
Juniper
Mx150
All versions
Juniper
Mx2008
All versions
Juniper
Mx2010
All versions
Juniper
Mx2020
All versions
Juniper
Mx204
All versions
Juniper
Mx240
All versions
Juniper
Mx40
All versions
Juniper
Mx480
All versions
Juniper
Mx5
All versions
Juniper
Mx80
All versions
Juniper
Mx960
All versions
Juniper
Srx100
All versions
Juniper
Srx110
All versions
Juniper
Srx1400
All versions
Juniper
Srx1500
All versions
Juniper
Srx210
All versions
Juniper
Srx220
All versions
Juniper
Srx240
All versions
Juniper
Srx240h2
All versions
Juniper
Srx240m
All versions
Juniper
Srx300
All versions
Juniper
Srx320
All versions
Juniper
Srx340
All versions
Juniper
Srx3400
All versions
Juniper
Srx345
All versions
Juniper
Srx3600
All versions
Juniper
Srx380
All versions
Juniper
Srx4000
All versions
Juniper
Srx4100
All versions
Juniper
Srx4200
All versions
Juniper
Srx4600
All versions
Juniper
Srx5000
All versions
Juniper
Srx5400
All versions
Juniper
Srx550
All versions
Juniper
Srx550 Hm
All versions
Juniper
Srx550m
All versions
Juniper
Srx5600
All versions
Juniper
Srx5800
All versions
Juniper
Srx650
All versions
Juniper
Vsrx
All versions

References (2)

Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.