An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) interface on the device, causing the packet forwarding engine (PFE) to crash, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.
This issue is only triggered by packets destined to a local-interface via a service-interface (AMS). AMS is only supported on the MS-MPC, MS-MIC, and MX-SPC3 cards. This issue is not experienced on other types of interfaces or configurations. Additionally, transit traffic does not trigger this issue.
This issue affects Juniper Networks Junos OS on MX Series:
A sample next-hop-service interface configuration is shown below:
set services service-set 3 next-hop-service inside-service-interface ams0.1
set services service-set 3 next-hop-service outside-service-interface ams0.2
set services nat rule 1 match-direction input
set services nat rule 1 term 1 from source-address 10.10.10.0/24
set services nat rule 1 term 1 then translated source-pool 1
set services nat rule 1 term 1 then translated translation-type napt-44
set services nat rule 1 term 1 then translated mapping-type endpoint-independent
set interfaces ams0 load-balancing-options member-interface mams-0/2/0
set routing-instances 2 routing-options static route 0.0.0.0/0 next-hop ams0.1
set routing-instances 2 instance-type virtual-router
set routing-instances 2 interface xe-0/0/0.0
set routing-instances 2 interface ams0.1
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was seen during production usage.
This issue has been assigned CVE-2023-36832.
The following software releases have been updated to resolve this specific issue: 19.1R3-S10, 19.2R3-S7, 19.3R3-S8, 19.4R3-S12, 20.2R3-S8, 20.4R3-S7, 21.1R3-S5, 21.2R3-S5, 21.3R3-S4, 21.4R3-S3, 22.1R3-S2, 22.2R3, 22.3R2-S1, 22.3R3, 22.4R1-S2, 22.4R2, 23.1R1, and all subsequent releases.
This issue is being tracked as 1707140
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
2023-07-12: Initial Publication