Product Affected

This issue affects all versions of Junos OS.
Medium
4.6 (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Problem

An Unexpected Status Code or Return Value vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated attacker with physical access to the device to cause a Denial of Service (DoS).

When certain USB devices are connected to a USB port of the routing-engine (RE), the kernel will crash leading to a reboot of the device. The device will continue to crash as long as the USB device is connected.


This issue affects Juniper Networks Junos OS:

All versions prior to 19.4R3-S10;

20.2 versions prior to 20.2R3-S7;

20.3 versions prior to 20.3R3-S6;

20.4 versions prior to 20.4R3-S5;

21.1 versions prior to 21.1R3-S4;

21.2 versions prior to 21.2R3-S4;

21.3 versions prior to 21.3R3-S3;

21.4 versions prior to 21.4R3-S2;

22.1 versions prior to 22.1R2-S2, 22.1R3;

22.2 versions prior to 22.2R2, 22.2R3;

22.3 versions prior to 22.3R1-S1, 22.3R2;

22.4 versions prior to 22.4R2.


Juniper SIRT is not aware of any malicious exploitation of this vulnerability.


This issue was seen during production usage.


This issue has been assigned CVE-2023-28975.

Solution

The following software releases have been updated to resolve this specific issue: 19.4R3-S10, 20.2R3-S7, 20.3R3-S6, 20.4R3-S5, 21.1R3-S4, 21.2R3-S4, 21.3R3-S3, 21.4R3-S2, 22.1R2-S2, 22.1R3, 22.2R2, 22.3R1-S1, 22.3R2, 22.4R2, 23.1R1, and all subsequent releases.


This issue is being tracked as 1638519


Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

To reduce the risk of exploitation utilize common security BCPs to limit physical access to the devices.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories.

Modification History

  • 2023-04-12: Initial Publication

Related Information