Product Affected

This issue affects all versions of Junos OS before 20.4R3-S10, 21.2, 21.4, 22.1, 22.2, 22.3, 22.4, 23.2.
High
CVSS 3.1: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS 4.0: 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)

Problem

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause Denial of Service (DoS).

The pkid is responsible for the certificate verification. Upon a failed verification, the pkid uses all CPU resources and becomes unresponsive to future verification attempts. This means that all subsequent VPN negotiations depending on certificate verification will fail.

This CPU utilization of pkid can be checked using this command:
  root@srx> show system processes extensive | match pkid
  xxxxx  root  103  0  846M  136M  CPU1  1 569:00 100.00% pkid


This issue affects:
Juniper Networks Junos OS
  • All versions prior to 20.4R3-S10;
  • 21.2 versions prior to 21.2R3-S7;
  • 21.4 versions prior to 21.4R3-S5;
  • 22.1 versions prior to 22.1R3-S4;
  • 22.2 versions prior to 22.2R3-S3;
  • 22.3 versions prior to 22.3R3-S1;
  • 22.4 versions prior to 22.4R3;
  • 23.2 versions prior to 23.2R1-S2, 23.2R2
To be affected by this issue, the following configuration is required on the device:
  [ security ike proposal <name> authentication-method rsa-signatures ]

Solution

The following software releases have been updated to resolve this specific issue: 20.4R3-S10, 21.2R3-S7, 21.4R3-S5, 22.1R3-S4, 22.2R3-S3, 22.3R3-S1, 22.4R3, 23.2R1-S2, 23.2R2, 23.4R1, and all subsequent releases.

This issue is being tracked as 1745288 which is visible on the Customer Support website.

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for this issue.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories.

Modification History

2024-04-10 - Initial Publication
2024-09-13: Minor formatting change to CVSS field

Related Information