NA

CVE-2023-44193

Published: 13/10/2023 Updated: 20/10/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An Improper Release of Memory Before Removing Last Reference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a local, low privileged malicious user to cause an FPC crash, leading to Denial of Service (DoS). On all Junos MX Series with MPC1 - MPC9, LC480, LC2101, MX10003, and MX80, when Connectivity-Fault-Management (CFM) is enabled in a VPLS scenario, and a specific LDP related command is run, an FPC will crash and reboot. Continued execution of this specific LDP command can lead to sustained Denial of Service condition. This issue affects: Juniper Networks Junos OS on MX Series: * All versions before 20.4R3-S7; * 21.1 versions before 21.1R3-S5; * 21.2 versions before 21.2R3-S4; * 21.3 versions before 21.3R3-S4; * 21.4 versions before 21.4R3-S3; * 22.1 versions before 22.1R3-S1; * 22.2 versions before 22.2R2-S1, 22.2R3; * 22.3 versions before 22.3R1-S2, 22.3R2.

Vulnerable Product Search on Vulmon Subscribe to Product

juniper junos

juniper junos 20.4

juniper junos 21.1

juniper junos 21.2

juniper junos 21.3

juniper junos 21.4

juniper junos 22.1

juniper junos 22.2

juniper junos 22.3