An Improperly Controlled Sequential Memory Allocation vulnerability in the Juniper Networks Deep Packet Inspection-Decoder (JDPI-Decoder) Application Signature component of Junos OS's AppID service on SRX Series devices will stop the JDPI-Decoder from identifying dynamic application traffic, allowing an unauthenticated network-based attacker to send traffic to the target device using the JDPI-Decoder, designed to inspect dynamic application traffic and take action upon this traffic, to instead begin to not take action and to pass the traffic through.
An example session can be seen by running the following command and evaluating the output.
user@device# run show security flow session source-prefix <address/mask> extensiveSession ID: <session ID>, Status: Normal, State: ActivePolicy name: <name of policy>Dynamic application: junos:UNKNOWN, <<<<< LOOK HERE
user@device# run show security flow session source-prefix <address/mask> extensive
Session ID: <session ID>, Status: Normal, State: Active
Policy name: <name of policy>
Dynamic application: junos:UNKNOWN, <<<<< LOOK HERE
Please note, the JDPI-Decoder and the AppID SigPack are both affected and both must be upgraded along with the operating system to address the matter. By default, none of this is auto-enabled for automatic updates.
This issue affects:
Juniper Networks any version of the JDPI-Decoder Engine prior to version 5.7.0-47 with the JDPI-Decoder enabled using any version of the AppID SigPack prior to version 1.550.2-31 (SigPack 3533) on Junos OS on SRX Series:
For this issue, Security Policy with dynamic application must be configured:
[security zones security-zone trust][security zones security-zone untrust][security policies from-zone “zone” to-zone “zone” policy “policy” match source-address “address”][security policies from-zone “zone” to-zone “zone” policy “policy” match destination-address “address”][security policies from-zone “zone” to-zone “zone” policy “policy” match dynamic-application “application”][security policies from-zone “zone” to-zone “zone” policy “policy” then “action”]
[security zones security-zone trust]
[security zones security-zone untrust]
[security policies from-zone “zone” to-zone “zone” policy “policy” match source-address “address”]
[security policies from-zone “zone” to-zone “zone” policy “policy” match destination-address “address”]
[security policies from-zone “zone” to-zone “zone” policy “policy” match dynamic-application “application”]
[security policies from-zone “zone” to-zone “zone” policy “policy” then “action”]
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was seen during production usage.
This issue has been assigned CVE-2023-28968.
The following software releases have been updated to resolve this specific issue: 19.4R3-S11, 20.2R3-S7, 20.4R3-S6, 21.1R3-S5, 21.2R3-S4, 21.3R3-S3, 21.4R3-S3, 22.1R3-S1, 22.2R2-S1, 22.2R3, 22.3R1-S2, 22.3R2, 22.4R1, and all subsequent releases.
Please note: Prior to Junos OS: 21.2R3-S4, 21.3R3-S3, 21.3R3-S3, 21.4R3-S3, 22.1R3-S1, 22.2R2-S1, 22.2R3, 22.3R2, 22.4R1, and all subsequent releases SOF is incorrectly offloading short-lived flows leading to early exhaustion of NP memory, reducing overall device performance. Customers should review PRSearch PR1692100 for such details in conjunction with this advisory.
Customers may choose to enable automatic updates for IDP or manually update the IDP security package to receive the fixes.
To manually download the IDP signatures:
a. Download the IDP security-package on the device:
request security idp security-package download
b. Check the status of the download:
request security idp security-package download status
c. Install the IDP security-package on the device:
request security idp security-package install
d. Check the status of the installation:
request security idp security-package install status
To enabled automatic update review the instuctions located at: https://supportportal.juniper.net/s/article/SRX-How-to-update-IDP-signature-database-automatically-on-a-SRX
== When using AppID only:
request services application-identification download
request services application-identification download status
request services application-identification install
request services application-identification install status
Or enable auto-update for AppID:
[edit]
user# set services application-identification download automatic ?
Possible completions:
interval Attempt to download new application package (hours)
start-time Start time(MM-DD.hh:mm / YYYY-MM-DD.hh:mm:ss)
Note: This updated signature package is not compatible with v4 engines.
This issue is being tracked as 1694222
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for this issue other than disabling the AppID service.
Additionally, a reboot will temporarily clear the problem until such time that updates can be taken. How long this lasts depends on the customer's network environment and the device being affected.