Access of uninitialized pointer in Junos OS and Junos OS Evolved - CVE-2023-22398
Published: January 11, 2023
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to access of uninitialized pointer error in the Routing Protocol Daemon (rpd). A remote non-authenticated attacker can cause a Denial of Service (DoS).
When an MPLS ping is performed on BGP LSPs, the RPD might crash.
Repeated execution of this operation will lead to a sustained DoS.
Affected software
Junos OS Evolved
How to mitigate CVE-2023-22398
Junos OS Evolved - addressed in versions 20.4R3-S4-EVO, 21.1R2-EVO, 21.2R1-EVO