Product Affected

This issue affects all versions of Junos OS. Affected platforms: SRX4600, SRX5000 Series.
Medium
CVSS 3.1: 5.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N)
CVSS 4.0: 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N)

Problem

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows an attacker to send TCP packets with SYN/FIN or SYN/RST flags, bypassing the expected blocking of these packets.

A TCP packet with SYN/FIN or SYN/RST should be dropped in flowd. However, when no-syn-check and Express Path are enabled, these TCP packets are unexpectedly transferred to the downstream network.
 

This issue affects Junos OS on SRX4600 and SRX5000 Series:

  • All versions before 21.2R3-S8,
  • from 21.4 before 21.4R3-S7,
  • from 22.1 before 22.1R3-S6,
  • from 22.2 before 22.2R3-S4,
  • from 22.3 before 22.3R3-S3,
  • from 22.4 before 22.4R3-S2,
  • from 23.2 before 23.2R2,
  • from 23.4 before 23.4R1-S1, 23.4R2.


This issue only affects systems with both no-syn-check and Express Path enabled:
[set security flow tcp-session no-syn-check]
[set security forwarding-options services-offload enable]

(This can also be enabled per security policy)

Note: Automated Express Path is enabled by default starting with Junos OS 21.2R1.

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue was seen during production usage.

Solution

The following software releases have been updated to resolve this specific issue: 21.2R3-S8, 21.4R3-S7, 22.1R3-S6, 22.2R3-S4, 22.3R3-S3, 22.4R3-S2, 23.2R2, 23.4R1-S1, 23.4R2, 24.2R1, and all subsequent releases.


This issue is being tracked as 1776940 which is visible on the Customer Support website.

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
 

Workaround

This issue can be mitigated by disabling Express Path:

[set security forwarding-options services-offload disable]

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2024-07-10: Initial Publication
2024-07-11: Corrected workaround
2024-09-13: Minor formatting change to CVSS field

Related Information