Product Affected

This issue affects Junos OS 20.4, 21.2, 21.4, 22.1, 22.2, 22.3, 22.4, 23.2. This issue affects Junos OS Evolved 21.4-EVO, 22.1-EVO, 22.2-EVO, 22.3-EVO, 22.4-EVO, 23.2-EVO.
Medium
CVSS 3.1: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS 4.0: 8.2 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)

Problem

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).

When telemetry requests are sent to the device, and the Dynamic Rendering Daemon (drend) is suspended, the l2ald crashes and restarts due to factors outside the attackers control. Repeated occurrences of these events causes a sustained DoS condition.
This issue is only seen when telemetry subscription is active.

This issue affects:
Junos OS:
  • All versions earlier than 20.4R3-S10;
  • 21.2 versions earlier than 21.2R3-S7;
  • 21.4 versions earlier than 21.4R3-S5;
  • 22.1 versions earlier than 22.1R3-S4;
  • 22.2 versions earlier than 22.2R3-S3;
  • 22.3 versions earlier than 22.3R3-S1;
  • 22.4 versions earlier than 22.4R3;
  • 23.2 versions earlier than 23.2R1-S2, 23.2R2.
Junos OS Evolved:
  • All versions earlier than 21.4R3-S5-EVO;
  • 22.1-EVO versions earlier than 22.1R3-S4-EVO;
  • 22.2-EVO versions earlier than 22.2R3-S3-EVO;
  • 22.3-EVO versions earlier than 22.3R3-S1-EVO;
  • 22.4-EVO versions earlier than 22.4R3-EVO;
  • 23.2-EVO versions earlier than 23.2R2-EVO.

Solution

The following software releases have been updated to resolve this specific issue:
Junos OS: 20.4R3-S10, 21.2R3-S7, 21.4R3-S5, 22.1R3-S4, 22.2R3-S3, 22.3R3-S1, 22.4R3, 23.2R1-S2, 23.2R2, 23.4R1, and all subsequent releases.
Junos OS Evolved: 21.4R3-S5-EVO, 22.1R3-S4-EVO, 22.2R3-S3-EVO, 22.3R3-S1-EVO, 22.4R3-EVO, 23.2R2-EVO, 23.4R1-EVO, and all subsequent releases.

This issue is being tracked as 1743744 which is visible on the Customer Support website.

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for this issue.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories.

Modification History

2024-04-10 - Initial Publication
2024-09-13: Minor formatting change to CVSS field

Related Information