CVSS: v3.1: 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)CVSS: v4.0: 7.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/RE:M)
An Allocation of Resources Without Limits or Throttling vulnerability in some processes of Juniper Networks Junos OS Evolved allows an authenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS).
When specific SNMP GET operations or specific low-priviledged CLI commands are executed, a GUID resource leak will occur, eventually leading to exhaustion and resulting in FPCs to hang. Affected FPCs need to be manually restarted to recover.
GUID exhaustion will trigger a syslog message like one of the following:
<process-name>[<pid>]: get_next_guid: Ran out of Guid Space ...
These issues affects Junos OS Evolved:
For these issues to be exploitable from the CLI there is no minimal configuration required. For these issues to be exploited via SNMP minimal SNMP configuration with at least read access is required:[ snmp community <name> ]or[ snmp v3 ... ]
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were found during internal product security testing or research.
The following software releases have been updated to resolve these specific issues: 21.4R3-S7-EVO, 22.2R3-EVO, 22.3R3-EVO, 22.4R2-EVO, 23.2R1-EVO, and all subsequent releases.
These issues are being tracked as 1713163, 1661578 and 1661618 which are visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for these issues.To reduce the risk of exploitation of these issues, use access lists or firewall filters to limit access to only trusted networks, hosts and users.
2024-10-09: Initial Publication2024-10-15: Added accidentally omitted CVE IDs. And corrected several occurrences from singular issue to plural issues.2024-11-04: Updated the JSA to reflect that more than the initially listed processes can be affected by guid leaks.