NA

CVE-2023-28984

Published: 17/04/2023 Updated: 01/05/2023
CVSS v3 Base Score: 5.3 | Impact Score: 3.6 | Exploitability Score: 1.6
VMScore: 0

Vulnerability Summary

A Use After Free vulnerability in the Layer 2 Address Learning Manager (l2alm) of Juniper Networks Junos OS on QFX Series allows an adjacent malicious user to cause the Packet Forwarding Engine to crash and restart, leading to a Denial of Service (DoS). The PFE may crash when a lot of MAC learning and aging happens, but due to a Race Condition (Concurrent Execution using Shared Resource with Improper Synchronization) that is outside the attackers direct control. This issue affects: Juniper Networks Junos OS versions before 19.4R3-S10 on QFX Series; 20.2 versions before 20.2R3-S7 on QFX Series; 20.3 versions before 20.3R3-S6 on QFX Series; 20.4 versions before 20.4R3-S5 on QFX Series; 21.1 versions before 21.1R3-S4 on QFX Series; 21.2 versions before 21.2R3-S3 on QFX Series; 21.3 versions before 21.3R3-S3 on QFX Series; 21.4 versions before 21.4R3 on QFX Series; 22.1 versions before 22.1R3 on QFX Series; 22.2 versions before 22.2R2 on QFX Series.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

juniper junos 20.2

juniper junos 20.3

juniper junos 20.4

juniper junos 21.1

juniper junos 21.2

juniper junos 21.3

juniper junos 21.4

juniper junos 22.1

juniper junos 22.2

juniper junos 22.3

juniper junos 22.4