Improper Check or Handling of Exceptional Conditions in Junos OS - CVE-2023-28959

 

Improper Check or Handling of Exceptional Conditions in Junos OS - CVE-2023-28959

Published: April 13, 2023


Vulnerability identifier: #VU75107
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28959
CWE-ID: CWE-703
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an error when processing network packets. A remote attacker on the local broadcast domain can send a malformed packet to the device, causing all PFEs other than the inbound PFE to wedge and to eventually restart.


Affected software

Junos OS
IBM Watson Knowledge Catalog in Cloud Pak for Data

How to mitigate CVE-2023-28959

Install updates from vendor's website.

Junos OS - addressed in versions 19.4R3-S11, 20.2R3-S7, 20.4R3-S6, 21.1R3-S4, 21.2R3-S4, 21.3R3-S3, 21.4R3-S2, 22.1R3-S1, 22.2R2-S1, 22.2R3, 22.3R1-S2, 22.3R2, 22.4R1
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.7

External References

Related Security Bulletins