Product Affected

This issue affects Junos OS 21.4. Affected platforms: EX4300 Series.
Medium
CVSS 3.1: 5.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N)
CVSS 4.0: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N

Problem

An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows an unauthenticated, network-based attacker to cause an integrity impact to networks downstream of the vulnerable device.

When an output firewall filter is applied to an interface it doesn't recognize matching packets but permits any traffic.

This issue affects Junos OS 21.4 releases from 21.4R1 earlier than 21.4R3-S6.
This issue doesn't not affect Junos OS releases earlier than 21.4R1.

To be affected by this issue an output firewall filter has to be configured on an interface like in the following example:

  [interfaces <interface> unit <unit> family <family> filter output <filter_name>]

Solution

The following software release has been updated to resolve this specific issue: 21.4R3-S6, and all subsequent releases of this branch.

This issue is being tracked as 1770410 which is visible on the Customer Support website.

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

While there is no known workarounds for this issue, it is possible to recover by deactivating and then activating the filter. But please note that the issue might reoccur after a reboot or pfe restart.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories.

Modification History

2024-04-10 - Initial Publication
2024-09-13: Minor formatting change to CVSS field

Related Information