SB2023101965 - Security restrictions bypass in multiple Junos OS user interfaces



SB2023101965 - Security restrictions bypass in multiple Junos OS user interfaces

Published: October 19, 2023

Security Bulletin ID SB2023101965
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Unchecked return value to null pointer dereference (CVE-ID: CVE-2023-44182)

The vulnerability allows a remote authenticated user to read and manipulate data.

The vulnerability exists due to unchecked return value error in the user interfaces. A remote authenticated user can read and manipulate data.

The vulnerability affects multiple user interfaces, such as CLI, the XML API, the XML Management Protocol, the NETCONF Management Protocol, the gNMI interfaces, and the J-Web User.


Remediation

Install update from vendor's website.