Product Affected

This issue affects all versions of Junos OS and Junos OS Evolved.
High

CVSS: v3.1: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVSS: v4.0: 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L)

Problem

A Buffer Access with Incorrect Length Value vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).

 

When an attacker sends a specific ICMPv6 packet to an interface with "protocols router-advertisement" configured, rpd crashes and restarts. Continued receipt of this packet will cause a sustained DoS condition. 

 

This issue only affects systems configured with IPv6.

 

This issue affects Junos OS: 

  • All versions before 21.2R3-S9, 
  • from 21.4 before 21.4R3-S10,
  • from 22.2 before 22.2R3-S6,
  • from 22.4 before 22.4R3-S4,
  • from 23.2 before 23.2R2-S2,
  • from 23.4 before 23.4R2;
and Junos OS Evolved:
  • All versions before 21.2R3-S9-EVO,
  • from 21.4-EVO before 21.4R3-S10-EVO,
  • from 22.2-EVO before 22.2R3-S6-EVO,
  • from 22.4-EVO before 22.4R3-S4-EVO,
  • from 23.2-EVO before 23.2R2-S2-EVO,
  • from 23.4-EVO before 23.4R2-EVO.

Required configuration for exposure:

The following configuration is required to be affected by this issue:
[ protocols router-advertisement interface <interface-name> ]
[ interfaces <interface-name> unit <unit> family inet6 address <ipv6-addr> ]

Solution

The following software releases have been updated to resolve this specific issue: 
Junos OS: 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S4, 23.2R2-S2, 23.4R2, 24.2R1, and all subsequent releases.
Junos OS Evolved: 21.2R3-S9-EVO, 21.4R3-S10-EVO, 22.2R3-S6-EVO, 22.4R3-S4-EVO, 23.2R2-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases.

 

This issue is being tracked as 1809088 which is visible on the Customer Support website.

 

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for this issue.

A firewall filter can be implemented to restrict ICMPv6 traffic.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2025-04-09: Initial Publication

Related Information