An Improper Check or Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600 allows a adjacent attacker to send specific traffic, which leads to packet flooding, resulting in a Denial of Service (DoS).

When a specific IGMP packet is received in an isolated VLAN, it is duplicated to all other ports under the primary VLAN, which causes a flood.

This issue affects QFX5000 series, EX2300, EX3400, EX4100, EX4400 and EX4600 platforms only.

This issue affects Juniper Junos OS on on QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600:



* All versions prior to 20.4R3-S5;
* 21.1 versions prior to 21.1R3-S4;
* 21.2 versions prior to 21.2R3-S3;
* 21.3 versions prior to 21.3R3-S5;
* 21.4 versions prior to 21.4R3-S2;
* 22.1 versions prior to 22.1R3;
* 22.2 versions prior to 22.2R3;
* 22.3 versions prior to 22.3R2.






Project Subscriptions

Vendors Products
Juniper Subscribe
Ex2300-24mp Subscribe
Ex2300-24p Subscribe
Ex2300-24t Subscribe
Ex2300-48mp Subscribe
Ex2300-48p Subscribe
Ex2300-48t Subscribe
Ex2300-c Subscribe
Ex2300m Subscribe
Ex4100-f Subscribe
Qfx5100 Subscribe
Qfx5100-96s Subscribe
Qfx5110 Subscribe
Qfx5120 Subscribe
Qfx5130 Subscribe
Qfx5200 Subscribe
Qfx5200-32c Subscribe
Qfx5200-48y Subscribe
Qfx5210 Subscribe
Qfx5210-64c Subscribe
Qfx5220 Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-48562 An Improper Check or Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600 allows a adjacent attacker to send specific traffic, which leads to packet flooding, resulting in a Denial of Service (DoS). When a specific IGMP packet is received in an isolated VLAN, it is duplicated to all other ports under the primary VLAN, which causes a flood. This issue affects QFX5000 series, EX2300, EX3400, EX4100, EX4400 and EX4600 platforms only. This issue affects Juniper Junos OS on on QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600: * All versions prior to 20.4R3-S5; * 21.1 versions prior to 21.1R3-S4; * 21.2 versions prior to 21.2R3-S3; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S2; * 22.1 versions prior to 22.1R3; * 22.2 versions prior to 22.2R3; * 22.3 versions prior to 22.3R2.
Fixes

Solution

The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S5, 21.1R3-S4, 21.2R3-S3, 21.3R3-S5, 21.4R3-S2, 22.1R3, 22.2R3, 22.3R2, 22.4R1, and all subsequent releases.


Workaround

There are no known workarounds for this issue.

References
History

Wed, 18 Sep 2024 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2024-09-17T16:09:42.727Z

Reserved: 2023-09-26T19:30:32.350Z

Link: CVE-2023-44203

cve-icon Vulnrichment

Updated: 2024-08-02T19:59:51.867Z

cve-icon NVD

Status : Modified

Published: 2023-10-13T00:15:12.987

Modified: 2024-11-21T08:25:26.010

Link: CVE-2023-44203

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses