Product Affected

This issue affects all versions of Junos OS and all versions of Junos OS Evolved.
Medium
6.5 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Problem

An Incomplete Cleanup vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS).
 

An rpd crash can occur when an MPLS TE tunnel configuration change occurs on a directly connected router.


This issue affects:

Juniper Networks Junos OS

  • All versions prior to 18.4R2-S7;
  • 19.1 versions prior to 19.1R3-S2;
  • 19.2 versions prior to 19.2R3;
  • 19.3 versions prior to 19.3R3;
  • 19.4 versions prior to 19.4R3;
  • 20.1 versions prior to 20.1R2;
  • 20.2 versions prior to 20.2R2.

Juniper Networks Junos OS Evolved

  • All versions prior to 19.2R3-EVO;
  • 19.3 versions prior to 19.3R3-EVO;
  • 19.4 versions prior to 19.4R3-EVO;
  • 20.1 versions prior to 20.1R3-EVO;
  • 20.2 versions prior to 20.2R2-EVO.

 

To be exposed to this issue both the following statements needs to be configured on the device running a vulnerable OS Version:

[protocols rsvp interface <interface> link-protection max-bypasses]
[protocols rsvp interface <interface> link-protection bandwidth]

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.


This issue was seen during production usage.


This issue has been assigned CVE-2023-22407.

Solution

The following software releases have been updated to resolve this specific issue:

Junos OS: 18.4R2-S7, 19.1R3-S2, 19.2R3, 19.3R3, 19.4R3, 20.1R2, 20.2R2, 20.3R1, and all subsequent releases.

Junos OS Evolved: 19.2R3-EVO, 19.3R3-EVO, 19.4R3-EVO, 20.1R3-EVO, 20.2R2-EVO, 20.3R1-EVO, and all subsequent releases.


This issue is being tracked as 1487333.


Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

Remove 'protocols rsvp interface <interface> link-protection max-bypasses'.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

  • 2023-01-11: Initial Publication

Related Information