Product Affected

This issue affects all versions of Junos OS. Affected platforms: MX Series with SPC3, SRX Series.
Medium
5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

Problem

An Unchecked Input for Loop Condition vulnerability in a NAT library of Juniper Networks Junos OS allows a local authenticated attacker with low privileges to cause a Denial of Service (DoS).
 

When an inconsistent "deterministic NAT" configuration is present on an SRX, or MX with SPC3 and then a specific CLI command is issued the SPC will crash and restart. Repeated execution of this command will lead to a sustained DoS.

Such a configuration is characterized by the total number of port blocks being greater than the total number of hosts. An example for such configuration is:

[ services nat source pool TEST-POOL address x.x.x.0/32 to x.x.x.15/32 ]
[ services nat source pool TEST-POOL port deterministic block-size 1008 ]
[ services nat source pool TEST-POOL port deterministic host address y.y.y.0/24]
[ services nat source pool TEST-POOL port deterministic include-boundary-addresses]

where according to the following calculation:

65536-1024=64512 (number of usable ports per IP address, implicit)

64512/1008=64 (number of port blocks per Nat IP)

x.x.x.0/32 to x.x.x.15/32 = 16 (NAT IP addresses available in NAT pool)

total port blocks in NAT Pool = 64 blocks per IP * 16 IPs = 1024 Port blocks

host address y.y.y.0/24 = 256 hosts (with include-boundary-addresses)

If the port block size is configured to be 4032, then the total port blocks are (64512/4032) * 16 = 256 which is equivalent to the total host addresses of 256, and the issue will not be seen.


This issue affects Juniper Networks Junos OS on SRX Series, and MX Series with SPC3:

  • All versions prior to 19.4R3-S10;
  • 20.1 version 20.1R1 and later versions;
  • 20.2 versions prior to 20.2R3-S6;
  • 20.3 versions prior to 20.3R3-S6;
  • 20.4 versions prior to 20.4R3-S5;
  • 21.1 versions prior to 21.1R3-S4;
  • 21.2 versions prior to 21.2R3-S3;
  • 21.3 versions prior to 21.3R3-S3;
  • 21.4 versions prior to 21.4R3-S1;
  • 22.1 versions prior to 22.1R2-S2, 22.1R3;
  • 22.2 versions prior to 22.2R2.


Juniper SIRT is not aware of any malicious exploitation of this vulnerability.


This issue was seen during production usage.


This issue has been assigned CVE-2023-22409.

Solution

The following software releases have been updated to resolve this specific issue: 19.4R3-S10, 20.2R3-S6, 20.3R3-S6, 20.4R3-S5, 21.1R3-S4, 21.2R3-S3, 21.3R3-S3, 21.4R3-S1, 22.1R2-S2, 22.1R3, 22.2R2, 22.3R1, and all subsequent releases.


This issue is being tracked as 1656798.


Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

Please ensure the deterministic NAT configuration is consistent as shown in the description of the problem section.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

  • 2023-01-11: Initial Publication

Related Information