An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS). An attacker who sends malformed TCP traffic via an interface configured with PPPoE, causes an infinite loop on the respective PFE. This results in consuming all resources and a manual restart is needed to recover. This issue affects interfaces with PPPoE configured and tcp-mss enabled. This issue affects Juniper Networks Junos OS * All versions prior to 20.4R3-S7; * 21.1 version 21.1R1 and later versions; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S3; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3; * 22.3 versions prior to 22.3R2-S2; * 22.4 versions prior to 22.4R2;
References
History

Wed, 18 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
CPEs cpe:2.3:o:juniper_networks:junos_os:*:*:*:*:*:*:*:*
Vendors & Products Juniper Networks
Juniper Networks junos Os
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published: 2023-10-12T22:58:14.922Z

Updated: 2024-09-18T18:01:47.921Z

Reserved: 2023-06-27T16:17:25.276Z

Link: CVE-2023-36841

cve-icon Vulnrichment

Updated: 2024-08-02T17:01:09.926Z

cve-icon NVD

Status : Analyzed

Published: 2023-10-12T23:15:10.967

Modified: 2023-10-17T16:03:01.293

Link: CVE-2023-36841

cve-icon Redhat

No data.