Product Affected

This issue affects all versions of Junos OS. Affected platforms: MX Series, SRX Series.
High
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Problem

An Out-of-Bounds Write vulnerability in the H.323 ALG of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).
 

On all MX Series and SRX Series platform, when H.323 ALG is enabled and specific H.323 packets are received simultaneously, a flow processing daemon (flowd) crash will occur. Continued receipt of these specific packets will cause a sustained Denial of Service (DoS) condition.


This issue affects:

Juniper Networks Junos OS on MX Series and SRX Series

  • All versions prior to 19.4R3-S10;
  • 20.2 versions prior to 20.2R3-S6;
  • 20.3 versions prior to 20.3R3-S6;
  • 20.4 versions prior to 20.4R3-S5;
  • 21.1 versions prior to 21.1R3-S4;
  • 21.2 versions prior to 21.2R3-S3;
  • 21.3 versions prior to 21.3R3-S3;
  • 21.4 versions prior to 21.4R3;
  • 22.1 versions prior to 22.1R2-S1, 22.1R3;
  • 22.2 versions prior to 22.2R1-S2, 22.2R2.


To be affected the H.323 ALG needs to be enabled, either implicitly / by default or by way of configuration. Please verify with:


Check if H.323 ALG is enabled by default with:

user@host> show security alg status | match H323
H323 : Enabled


Configure H.323 ALG to receive incoming calls with following commands.

[set interfaces ge-0/0/0 unit 0 family inet address 10.1.1.1/24]
[set interfaces ge-0/0/1 unit 0 family inet address 172.16.1.1/24]
[set security zones security-zone private address-book address IP-Phone1 10.1.1.5/32]  
[set security zones security-zone private address-book address gatekeeper 10.1.1.25/32 ]
[set security zones security-zone private interfaces ge-0/0/0.0 ]
[set security zones security-zone public address-book address IP-Phone2 172.16.1.5/32 ]
[set security zones security-zone public interfaces ge-0/0/1.0]
[set security policies from-zone private to-zone public policy private-to-public match source-address IP-Phone1 ]
[set security policies from-zone private to-zone public policy private-to-public match source-address gatekeeper ]
[set security policies from-zone private to-zone public policy private-to-public match destination-address IP-Phone2 ]
[set security policies from-zone private to-zone public policy private-to-public match application junos-h323 ]
[set security policies from-zone private to-zone public policy private-to-public then permit ]
[set security policies from-zone public to-zone private policy public-to-private match source-address IP-Phone2 ]
[set security policies from-zone public to-zone private policy public-to-private match destination-address IP-Phone1 ]
[set security policies from-zone public to-zone private policy public-to-private match destination-address gatekeeper]
[set security policies from-zone public to-zone private policy public-to-private match application junos-h323 ]
[set security policies from-zone public to-zone private policy public-to-private then permit ]


Juniper SIRT is not aware of any malicious exploitation of this vulnerability.


This issue was seen during production usage.


This issue has been assigned CVE-2023-22415.

Solution

The following software releases have been updated to resolve this specific issue: 19.4R3-S10, 20.2R3-S6, 20.3R3-S6, 20.4R3-S5, 21.1R3-S4, 21.2R3-S3, 21.3R3-S3, 21.4R3, 22.1R2-S1, 22.1R3, 22.2R1-S2, 22.2R2, 22.3R1, and all subsequent releases.
 

This issue is being tracked as 1666996.
 

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for this issue, but it should be considered to disable the H.323 ALG if it's not strictly needed.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

  • 2023-01-11: Initial Publication

Related Information