#VU75095 Improper Check for Unusual or Exceptional Conditions in Juniper Junos OS - CVE-2023-28976

 

#VU75095 Improper Check for Unusual or Exceptional Conditions in Juniper Junos OS - CVE-2023-28976

Published: April 13, 2023


Vulnerability identifier: #VU75095
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-28976
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Juniper Junos OS
Software vendor:
Juniper Networks, Inc.

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling in the packet forwarding engine (pfe). If specific traffic is received on MX Series and its rate exceeds the respective DDoS protection limit the ingress PFE will crash and restart.


Remediation

Install updates from vendor's website.

External links