SB2023041343 - Denial of service in Junos OS PFE



SB2023041343 - Denial of service in Junos OS PFE

Published: April 13, 2023

Security Bulletin ID SB2023041343
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2023-28976)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling in the packet forwarding engine (pfe). If specific traffic is received on MX Series and its rate exceeds the respective DDoS protection limit the ingress PFE will crash and restart.


Remediation

Install update from vendor's website.