Product Affected

This issue affects all versions of Junos OS
Medium
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Problem

An Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby resulting in a Denial of Service (DoS).
 

Upon receiving malformed SSL traffic, the PFE crashes. A manual restart will be needed to recover the device.
 

This issue only affects devices with Juniper Networks Advanced Threat Prevention (ATP) Cloud enabled with Encrypted Traffic Insights (configured via ‘security-metadata-streaming policy’).
 

This issue affects Juniper Networks Junos OS:

All versions prior to 20.4R3-S8, 20.4R3-S9;

21.1 version 21.1R1 and later versions;

21.2 versions prior to 21.2R3-S6;

21.3 versions prior to 21.3R3-S5;

21.4 versions prior to 21.4R3-S5;

22.1 versions prior to 22.1R3-S4;

22.2 versions prior to 22.2R3-S2;

22.3 versions prior to 22.3R2-S2, 22.3R3;

22.4 versions prior to 22.4R2-S1, 22.4R3;
 

The below command configures security-metadata-streaming:
[set services security-metadata-streaming-policy]
 

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.


This issue was found during internal product security testing or research.


This issue has been assigned CVE-2023-36843.

Solution

The following software releases have been updated to resolve this specific issue: Junos OS 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S2, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3, 23.1R2, 23.2R1, and all subsequent releases.
 

This issue is being tracked as PR 1696110 which is visible on the Customer Support website.


Note: Juniper SIRT's policy [juniper.net] is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

Removing the security-metadata-streaming policy from the configuration stops the issue.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2023-10-11: Initial Publication

Related Information