An Improper Restriction of Operations within the Bounds...
High severity
Unreviewed
Published
Apr 12, 2024
to the GitHub Advisory Database
•
Updated May 26, 2024
Description
Published by the National Vulnerability Database
Apr 12, 2024
Published to the GitHub Advisory Database
Apr 12, 2024
Last updated
May 26, 2024
An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).
When a high amount of specific traffic is received on a SRX4600 device, due to an error in internal packet handling, a consistent rise in CPU memory utilization occurs. This results in packet drops in the traffic and eventually the PFE crashes. A manual reboot of the PFE will be required to restore the device to original state.
This issue affects Junos OS:
21.2 before 21.2R3-S7,
21.4 before 21.4R3-S6,
22.1 before 22.1R3-S5,
22.2 before 22.2R3-S3,
22.3 before 22.3R3-S2,
22.4 before 22.4R3,
23.2 before 23.2R1-S2, 23.2R2.
References