Improper Check for Unusual or Exceptional Conditions in Junos OS - CVE-2023-28976

 

Improper Check for Unusual or Exceptional Conditions in Junos OS - CVE-2023-28976

Published: April 13, 2023


Vulnerability identifier: #VU75095
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28976
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling in the packet forwarding engine (pfe). If specific traffic is received on MX Series and its rate exceeds the respective DDoS protection limit the ingress PFE will crash and restart.


Affected software

Junos OS

How to mitigate CVE-2023-28976

Install updates from vendor's website.

Junos OS - addressed in versions 19.4R3-S11, 20.2R3-S5, 20.4R3-S6, 21.1R3-S5, 21.2R3-S4, 21.3R3, 21.4R3, 22.1R2, 22.2R1

External References

Related Security Bulletins