CVSS: v3.1: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)CVSS: v4.0: 8.2 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L)
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause Denial of Service (DoS).When a BGP UPDATE with malformed path attribute is received over an established BGP session, rpd crashes and restarts.Continuous receipt of a BGP UPDATE with a specifically malformed path attribute will create a sustained Denial of Service (DoS) condition for impacted devices. While this issue affects systems running 32-bit and 64-bit systems, the probability of impact on 64-bit system is extremely low.
According to KB25803 [juniper.net], customers can confirm 32-bit Junos OS software via the ' show version detail ' command: lab@router> show version detail| match 32 JUNOS 32-bit kernel Software Suite
show version detail
lab@router> show version detail| match 64 JUNOS 64-bit kernel Software Suite
This issue affects:
Juniper Networks Junos OS:
Juniper Networks Junos OS Evolved:
To be exposed to this issue a minimal BGP configuration like the following is required: [ protocols bgp group <name> neighbor ... ]
The following software releases have been updated to resolve this specific issue:Junos OS: 21.4R3-S8, 22.2R3-S4, 22.4R3-S3, 23.2R2-S1, 23.4R1-S2, 23.4R2, 24.2R1, and all subsequent releases.Junos OS Evolved: 21.4R3-S8-EVO, 22.2R3-S4-EVO, 22.4R3-S3-EVO, 23.2R2-S1-EVO, 23.4R1-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases.
This issue is being tracked as 1797147 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for this issue.
2024-10-09: Initial Publication2024-10-15: Added required minimal BGP configuration and method of confirming 32-bit system2024-10-16: Changed CVSS to reflect the Attack Complexity to High and corrected 32-bit and 64-bit systems are vulnerable however, impact on 64-bit system is extremely low.