An Out-of-Bounds Write vulnerability in the H.323 ALG of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).
On all MX Series and SRX Series platform, when H.323 ALG is enabled and specific H.323 packets are received simultaneously, a flow processing daemon (flowd) crash will occur. Continued receipt of these specific packets will cause a sustained Denial of Service (DoS) condition.
This issue affects:
Juniper Networks Junos OS on MX Series and SRX Series
To be affected the H.323 ALG needs to be enabled, either implicitly / by default or by way of configuration. Please verify with:
Check if H.323 ALG is enabled by default with:
user@host> show security alg status | match H323
H323 : Enabled
Configure H.323 ALG to receive incoming calls with following commands.
[set interfaces ge-0/0/0 unit 0 family inet address 10.1.1.1/24]
[set interfaces ge-0/0/1 unit 0 family inet address 172.16.1.1/24]
[set security zones security-zone private address-book address IP-Phone1 10.1.1.5/32]
[set security zones security-zone private address-book address gatekeeper 10.1.1.25/32 ]
[set security zones security-zone private interfaces ge-0/0/0.0 ]
[set security zones security-zone public address-book address IP-Phone2 172.16.1.5/32 ]
[set security zones security-zone public interfaces ge-0/0/1.0]
[set security policies from-zone private to-zone public policy private-to-public match source-address IP-Phone1 ]
[set security policies from-zone private to-zone public policy private-to-public match source-address gatekeeper ]
[set security policies from-zone private to-zone public policy private-to-public match destination-address IP-Phone2 ]
[set security policies from-zone private to-zone public policy private-to-public match application junos-h323 ]
[set security policies from-zone private to-zone public policy private-to-public then permit ]
[set security policies from-zone public to-zone private policy public-to-private match source-address IP-Phone2 ]
[set security policies from-zone public to-zone private policy public-to-private match destination-address IP-Phone1 ]
[set security policies from-zone public to-zone private policy public-to-private match destination-address gatekeeper]
[set security policies from-zone public to-zone private policy public-to-private match application junos-h323 ]
[set security policies from-zone public to-zone private policy public-to-private then permit ]
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was seen during production usage.
This issue has been assigned CVE-2023-22415.
The following software releases have been updated to resolve this specific issue: 19.4R3-S10, 20.2R3-S6, 20.3R3-S6, 20.4R3-S5, 21.1R3-S4, 21.2R3-S3, 21.3R3-S3, 21.4R3, 22.1R2-S1, 22.1R3, 22.2R1-S2, 22.2R2, 22.3R1, and all subsequent releases.
This issue is being tracked as 1666996.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
2023-01-11: Initial Publication