← Back

CVE-2023-44193

nvd nist
Published: Oct 13, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

An Improper Release of Memory Before Removing Last Reference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a local, low privileged attacker to cause an FPC crash, leading to Denial of Service (DoS). On all Junos MX Series with MPC1 - MPC9, LC480, LC2101, MX10003, and MX80, when Connectivity-Fault-Management (CFM) is enabled in a VPLS scenario, and a specific LDP related command is run, an FPC will crash and reboot. Continued execution of this specific LDP command can lead to sustained Denial of Service condition. This issue affects: Juniper Networks Junos OS on MX Series: * All versions prior to 20.4R3-S7; * 21.1 versions prior to 21.1R3-S5; * 21.2 versions prior to 21.2R3-S4; * 21.3 versions prior to 21.3R3-S4; * 21.4 versions prior to 21.4R3-S3; * 22.1 versions prior to 22.1R3-S1; * 22.2 versions prior to 22.2R2-S1, 22.2R3; * 22.3 versions prior to 22.3R1-S2, 22.3R2.

Affected (70)

Products: Juniper: Junos
1 product
Junos
Configuration A
70 vulnerable · 11 platform
Vulnerable SoftwareAffected Versions
Juniper
Before 20.4
Version 20.4
Version 20.4 r1-s1
Version 20.4 r1
Version 20.4 r2-s1
Version 20.4 r2-s2
Version 20.4 r2
Version 20.4 r3-s1
Version 20.4 r3-s2
Version 20.4 r3-s3
Version 20.4 r3-s4
Version 20.4 r3-s5
Version 20.4 r3-s6
Version 20.4 r3
Version 21.1
Version 21.1 r1-s1
Version 21.1 r1
Version 21.1 r2-s1
Version 21.1 r2-s2
Version 21.1 r2
Version 21.1 r3-s1
Version 21.1 r3-s2
Version 21.1 r3-s3
Version 21.1 r3-s4
Version 21.1 r3
Version 21.2
Version 21.2 r1-s1
Version 21.2 r1-s2
Version 21.2 r1
Version 21.2 r2-s1
Version 21.2 r2-s2
Version 21.2 r2
Version 21.2 r3-s1
Version 21.2 r3-s2
Version 21.2 r3-s3
Version 21.2 r3
Version 21.3
Version 21.3 r1-s1
Version 21.3 r1-s2
Version 21.3 r1
Version 21.3 r2-s1
Version 21.3 r2-s2
Version 21.3 r2
Version 21.3 r3-s1
Version 21.3 r3-s2
Version 21.3 r3-s3
Version 21.3 r3
Version 21.4
Version 21.4 r1-s1
Version 21.4 r1-s2
Version 21.4 r1
Version 21.4 r2-s1
Version 21.4 r2-s2
Version 21.4 r2
Version 22.1 r1-s1
Version 22.1 r1-s2
Version 22.1 r1
Version 22.1 r2-s1
Version 22.1 r2-s2
Version 22.1 r2
Version 22.1 r3
Version 22.2
Version 22.2 r1-s1
Version 22.2 r1-s2
Version 22.2 r1
Version 22.2 r2
Version 22.3 r1-s1
Version 22.3 r1-s2
Version 22.3 r1
Version 22.3 r2
Running on/withPlatform Versions
Juniper
Mx10003
All versions
Juniper
Mx10004
All versions
Juniper
Mx10008
All versions
Juniper
Mx2008
All versions
Juniper
Mx2010
All versions
Juniper
Mx2020
All versions
Juniper
Mx204
All versions
Juniper
Mx240
All versions
Juniper
Mx304
All versions
Juniper
Mx480
All versions
Juniper
Mx960
All versions

References (2)

Source: sirt@juniper.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.