An Incomplete Cleanup vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS).
An rpd crash can occur when an MPLS TE tunnel configuration change occurs on a directly connected router.
This issue affects:
Juniper Networks Junos OS
Juniper Networks Junos OS Evolved
To be exposed to this issue both the following statements needs to be configured on the device running a vulnerable OS Version:
[protocols rsvp interface <interface> link-protection max-bypasses][protocols rsvp interface <interface> link-protection bandwidth]Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
[protocols rsvp interface <interface> link-protection max-bypasses]
[protocols rsvp interface <interface> link-protection bandwidth]
This issue was seen during production usage.
This issue has been assigned CVE-2023-22407.
The following software releases have been updated to resolve this specific issue:
Junos OS: 18.4R2-S7, 19.1R3-S2, 19.2R3, 19.3R3, 19.4R3, 20.1R2, 20.2R2, 20.3R1, and all subsequent releases.
Junos OS Evolved: 19.2R3-EVO, 19.3R3-EVO, 19.4R3-EVO, 20.1R3-EVO, 20.2R2-EVO, 20.3R1-EVO, and all subsequent releases.
This issue is being tracked as 1487333.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
2023-01-11: Initial Publication