Product Affected

This issue affects all versions of Junos OS. Affected platforms: MX Series.
High
7.4 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)

Problem

An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).

In a Broadband Edge / Subscriber Management scenario on MX Series when a specifically malformed ICMP packet addressed to the device is received from a subscriber the bbe-smgd will crash, affecting the subscriber sessions that are connecting, updating, or terminating. Continued receipt of such packets will lead to a sustained DoS condition.

When this issue happens the below log can be seen if the traceoptions for the processes smg-service are enabled:

BBE_TRACE(TRACE_LEVEL_INFO, "%s: Dropped unsupported ICMP PKT ...
 

This issue affects Juniper Networks Junos OS on MX Series:

All versions prior to 19.4R3-S11;

20.2 versions prior to 20.2R3-S7;

20.3 versions prior to 20.3R3-S6;

20.4 versions prior to 20.4R3-S6;

21.1 versions prior to 21.1R3-S4;

21.2 versions prior to 21.2R3-S4;

21.3 versions prior to 21.3R3-S3;

21.4 versions prior to 21.4R3-S2;

22.1 versions prior to 22.1R2-S2, 22.1R3;

22.2 versions prior to 22.2R2;

22.3 versions prior to 22.3R1-S2, 22.3R2.


To be exposed to this vulnerability subscriber management needs to be enabled via:

[system services subscriber-management enable]


Juniper SIRT is not aware of any malicious exploitation of this vulnerability.


This issue was seen during production usage.


This issue has been assigned CVE-2023-28974.

Solution

The following software releases have been updated to resolve this specific issue: 19.4R3-S11, 20.2R3-S7, 20.3R3-S6, 20.4R3-S6, 21.1R3-S4, 21.2R3-S4, 21.3R3-S3, 21.4R3-S2, 22.1R2-S2, 22.1R3, 22.2R2, 22.3R1-S2, 22.3R2, 22.4R1, and all subsequent releases.

This issue is being tracked as 1681389

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for this issue.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories.

Modification History

  • 2023-04-12: Initial Publication

Related Information