SB2023011183 - Improper check or handling of exceptional conditions in Juniper Junos OS



SB2023011183 - Improper check or handling of exceptional conditions in Juniper Junos OS

Published: January 11, 2023

Security Bulletin ID SB2023011183
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper check or handling of exceptional conditions (CVE-ID: CVE-2023-22413)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper check or handling of exceptional conditions error in the IPsec library. A remote non-authenticated attacker can cause Denial of Service (DoS).

 On all MX platforms with MS-MPC or MS-MIC card, when specific IPv4 packets are processed by an IPsec6 tunnel, the Multiservices PIC Management Daemon (mspmand) process will core and restart.

This will lead to FPC crash.


Remediation

Install update from vendor's website.