NA

CVE-2023-44204

Published: 13/10/2023 Updated: 19/10/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An Improper Validation of Syntactic Correctness of Input vulnerability in Routing Protocol Daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based malicious user to cause a Denial of Service (DoS). When a malformed BGP UPDATE packet is received over an established BGP session, the rpd crashes and restarts. This issue affects both eBGP and iBGP implementations. This issue affects: Juniper Networks Junos OS * 21.4 versions before 21.4R3-S4; * 22.1 versions before 22.1R3-S3; * 22.2 versions before 22.2R3-S2; * 22.3 versions before 22.3R2-S2, 22.3R3; * 22.4 versions before 22.4R2-S1, 22.4R3; * 23.2 versions before 23.2R1, 23.2R2; Juniper Networks Junos OS Evolved * 21.4 versions before 21.4R3-S5-EVO; * 22.1 versions before 22.1R3-S3-EVO; * 22.2 versions before 22.2R3-S3-EVO; * 22.3 versions before 22.3R2-S2-EVO; * 22.4 versions before 22.4R3-EVO; * 23.2 versions before 23.2R2-EVO;

Vulnerable Product Search on Vulmon Subscribe to Product

juniper junos 21.4

juniper junos 22.1

juniper junos 22.2

juniper junos 22.3

juniper junos 22.4

juniper junos 23.2

juniper junos os evolved 21.4

juniper junos os evolved 22.1

juniper junos os evolved 22.2

juniper junos os evolved 22.3

juniper junos os evolved 22.4

juniper junos os evolved 23.2