SB2023011167 - Denial of service in Junos OS on QFX10k series routers



SB2023011167 - Denial of service in Junos OS on QFX10k series routers

Published: January 11, 2023 Updated: October 25, 2023

Security Bulletin ID SB2023011167
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Allocation of resources without limits or throttling (CVE-ID: CVE-2023-22403)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to allocation of resources without limits or throttling error in the Packet Forwarding Engine (PFE). A remote non-authenticated attacker can cause a Denial of Service (DoS).

On QFX10k Series Inter-Chassis Control Protocol (ICCP) is used in MC-LAG topologies to exchange control information between the devices in the topology. ICCP connection flaps and sync issues will be observed due to excessive specific traffic to the local device


Remediation

Install update from vendor's website.