Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

Junos 19.1R3 FIPS and respective SRs for EX2300, EX3400, MX240-960, MX104, EX9200

Alert Description

Junos Software Service Release version 19.1R3-S13 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

Junos Software service Release version 19.1R3-S13 is now available.

19.1R3-S13 - List of Fixed issues

PR NumberSynopsisCategory: Flow Module
1820291Junos OS: SRX4600 and SRX5000 Series: Sequence of specific PIM packets causes a flowd crash (CVE-2024-47503)
Product-Group=junos
Severity=Critical
An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows an unauthenticated and logically adjacent attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88133 [juniper.net] for more information.
PR NumberSynopsisCategory: Platform infra to support jvision
1769294Junos OS: Due to a race condition AgentD process causes a memory corruption and FPC reset (CVE-2024-47494)
Product-Group=junos
Severity=Critical
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to established sessions which generates counter changes picked up by the AgentD process during telemetry polling, to move the AgentD process into a state where AgentD attempts to reap an already destroyed sensor. This reaping attempt then leads to memory corruption causing the FPC to crash which is a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88121 [juniper.net] for more information.
PR NumberSynopsisCategory: Protocol Independant Multicast
1709038Junos OS and Junos OS Evolved: Receipt of specific PIM packet causes rpd crash when PIM is configured along with MoFRR (CVE-2024-39558)
Product-Group=junos
Severity=Major
An Unchecked Return Value vulnerability in the Routing Protocol Daemon (rpd) on Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows a logically adjacent, unauthenticated attacker sending specific PIM packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS), when PIM is configured with Multicast-only Fast Reroute (MoFRR). Continued receipt and processing of this packet may create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA83018 [juniper.net] for more information.
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1480648Junos OS and Junos OS Evolved: Flaps of BFD sessions with authentication cause a ppmd memory leak (CVE-2024-39536)
Product-Group=junos
Severity=Major
A Missing Release of Memory after Effective Lifetime vulnerability in the Periodic Packet Management Daemon (ppmd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA82996 [juniper.net] for more information.
PR NumberSynopsisCategory: SRX Argon module
1815751Junos OS: SRX Series: Low privileged user able to access sensitive information on file system (CVE-2024-39527)
Product-Group=junos
Severity=Critical
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged user with access to the Junos CLI to view the contents of protected files on the file system. Please refer to https://supportportal.juniper.net/JSA88104 [juniper.net] for more information.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1784593Junos OS: MX Series: The PFE will crash on running specific command (CVE-2024-47496)
Product-Group=junos
Severity=Major
A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88123 [juniper.net] for more information.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1802329Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
Severity=Major
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

 


 

19.1R3-S13 - List of Known Issues

PR NumberSynopsisCategory: EX2300/3400 platform
PR NumberSynopsisCategory: SRX DNS DGA and tunneling related
1755484Junos OS: SRX Series: If DNS traceoptions are configured in a DGA or tunnel detection scenario specific DNS traffic leads to a PFE crash (CVE-2024-39529)
Product-Group=junos
A Use of Externally-Controlled Format String vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA82988 [juniper.net] for more information.

Resolved In: junos:21.4R3-S6 junos:22.2R3-S3 junos:22.3R3-S3 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: Border Gateway Protocol
1744801Junos OS and Junos OS Evolved: BGP multipath incremental calculation is resulting in an rpd crash (CVE-2024-39554)
Product-Group=junos
A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to inject incremental routing updates when BGP multipath is enabled, causing rpd to crash and restart, resulting in a Denial of Service (DoS). Since this is a timing issue (race condition), the successful exploitation of this vulnerability is outside the attacker's control. However, continued receipt and processing of this packet may create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA83014 [juniper.net] for more information.

Resolved In: evo:21.4R3-S6-EVO evo:22.1R3-S5-EVO evo:22.2R3-S3-EVO evo:22.2X100-EVO evo:22.3R3-S2-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:21.2R3-S7 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1 junos:24.2R2
1787290Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP update causes the session to reset (CVE-2024-39555)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker sending a specific malformed BGP update message to cause the session to reset, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83015 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.4R3-S3-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:21.4R3-S8 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R1-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1
1797147Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP path attribute leads to an RPD crash (CVE-2024-47491)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88116 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3X50-EVO evo:22.4R3-S3-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S9 junos:21.4R3-S8 junos:22.2R3-S4 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R1-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1 junos:24.3R2
1807533Junos OS and Junos OS Evolved: When BGP traceoptions is enabled, receipt of specially crafted BGP packet causes RPD crash (CVE-2024-39525)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specific BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA88102 [juniper.net] for more information.

Resolved In: evo:21.2R3-S8-EVO evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:22.4R3-S3-EVO evo:23.2R2-S1-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S8 junos:21.4R3-S8 junos:22.2R3-S4 junos:22.3R3-S4 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R2 junos:23.4R2-S1 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1814083Junos OS and Junos OS Evolved: With BGP traceoptions enabled, receipt of specifically malformed BGP update causes RPD crash (CVE-2024-39515)
Product-Group=junos
An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA88099 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S5-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:22.4R3-S3-EVO evo:23.2R2-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S9 junos:21.4R3-S8 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S3 junos:23.2R2-S2 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1815222Junos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crash (CVE-2024-39516)
Product-Group=junos
An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to send a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue only affects systems with BGP traceoptions enabled. Please refer to https://supportportal.juniper.net/JSA88100 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S5-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:22.4R3-S3-EVO evo:23.2R2-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S9 junos:21.4R3-S8 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S3 junos:23.2R2-S2 junos:23.4R2 junos:23.4R2-S1 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: EVO Layer-2 switching for BCM XGS Platforms
1705911Junos OS Evolved: QFX5000 Series: Configured MAC learning and move limits are not in effect (CVE-2024-47498)
Product-Group=junos
An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS Evolved on QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88128 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S5-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO evo:23.4R2-EVO junos:20.4R3-S8 junos:21.2R3-S6 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: ChassisD changes specific for DNX series.
1708557Junos OS: Attempting to access specific sensors on platforms not supporting these will lead to a chassisd crash (CVE-2024-39530)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis management daemon (chassisd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA82989 [juniper.net] for more information.

Resolved In: junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3 junos:22.2R3-S2 junos:22.3R2-S2 junos:22.3R3 junos:22.4R2 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1811734The LFM session flaps will be observed at random
Product-Group=junos
On Junos ACX5448 & ACX710 platforms with LFM (Link-fault-management) configured in distributed mode, the LFM session flaps will be seen at random when the peer device has LFM configured in inline mode. This will result in traffic loss.

Resolved In: junos:21.2R3-S9 junos:21.4R3-S9 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: EX interfaces issues
1580560On EX2300, EX3400, :EX4300-48MP and EX4300 , Pause frames counters does not get incremented when pause frames are sent.
Product-Group=junos
On EX2300, EX3400, :EX4300-48MP and EX4300 , Pause frames counters does not get incremented when pause frames are sent.

Resolved In:
PR NumberSynopsisCategory: IPSEC/IKE VPN
1716092Junos OS: SRX Series and MX Series with SPC3 and NFX350: When VPN tunnels parameters are not matching the iked process will crash (CVE-2024-39545)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on SRX Series, MX Series with SPC3 and NFX350 allows an unauthenticated, network-based attacker sending specific mismatching parameters as part of the IPsec negotiation to trigger an iked crash leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83007 [juniper.net] for more information.

Resolved In: junos:21.2R3-S8 junos:21.4R3-S7 junos:22.1R3-J1 junos:22.1R3-S2 junos:22.2R3-S1 junos:22.3R2-S1 junos:22.3R3 junos:22.4R1-S2 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Security platform jweb support
1725808Junos OS: J-Web: Multiple vulnerabilities resolved in PHP software (CVE-2023-0567, CVE-2023-0662, CVE-2023-3823, CVE-2023-3824, CVE-2023-0568)
Product-Group=junos
PHP software included with Juniper Networks Junos OS J-Web has been updated to resolve multiple vulnerabilities. Please refer to https://supportportal.juniper.net/JSA88120 [juniper.net] for more information.

Resolved In: evo:23.3R2-EVO junos:21.4R3-S8 junos:22.1R3-S6 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S2 junos:23.2R1-S2 junos:23.2R2 junos:23.2R2-S2 junos:23.3R2 junos:23.4R1 junos:23.4R1-S2 junos:23.4R2 junos:24.1R1 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1783346Junos OS and Junos OS Evolved: Upon processing specific L2 traffic, rpd can hang in devices with EVPN/VXLAN configured (CVE-2024-39517)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) on Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA79175 [juniper.net] for more information.

Resolved In: evo:21.2R3-S8-EVO evo:21.4R3-S7-EVO evo:22.1R3-S5-EVO evo:22.2R3-S3-EVO evo:22.3R3-S3-EVO evo:22.4R3-S2-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:20.2R3-S9 junos:21.2R3-S8 junos:21.4R3-S7 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S2 junos:23.2R2 junos:23.2R2-J14 junos:23.4R1-S1 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: Issues related to control plane security
1780283Junos OS and Junos OS Evolved: Loading a malicious certificate from the CLI may result in a stack-based overflow (CVE-2024-39556)
Product-Group=junos
A Stack-Based Buffer Overflow vulnerability in Juniper Networks Junos OS and Juniper Networks Junos OS Evolved may allow a local, low-privileged attacker with access to the CLI the ability to load a malicious certificate file, leading to a limited Denial of Service (DoS) or privileged code execution. Please refer to https://supportportal.juniper.net/JSA83016 [juniper.net] for more information.

Resolved In: evo:21.2R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X80-D45-EVO evo:23.2R2-S2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.2R1-EVO junos:19.4R3-S14 junos:20.2R3-S9 junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S8 junos:21.4R3-S7 junos:22.1R3-S6 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S2 junos:23.2R2 junos:23.2R2-S2 junos:23.4R1-S1 junos:23.4R1-S1-J6 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: SRX Argon module
1661766Junos OS: SRX Series: A large amount of traffic being processed by ATP Cloud can lead to a PFE crash (CVE-2024-47506)
Product-Group=junos
A Deadlock vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88137 [juniper.net] for more information.

Resolved In: junos:19.2R3-S10 junos:21.3R3-S1 junos:21.4R3 junos:22.1R2 junos:22.2R1-S2 junos:22.2R2 junos:22.2R3-S6 junos:22.3R1
PR NumberSynopsisCategory: SRX branch platforms
1777464Junos OS: Multiple vulnerabilities in OSS component nginx resolved (CVE-2023-44487)
Product-Group=junos
Multiple vulnerabilities have been resolved in nginx software included with Juniper Networks Junos OS by upgrading nginx to version 1.22.1 or by applying specific fixes. Please refer to https://supportportal.juniper.net/JSA88135 [juniper.net] for more information.

Resolved In: junos:23.2R2-S2 junos:23.4R2-S1 junos:24.1R1 junos:24.2R1
1783757Junos OS: SRX Series, QFX Series, MX Series and EX Series: Receiving specific HTTPS traffic causes resource exhaustion (CVE-2024-47497)
Product-Group=junos
An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series, QFX Series, MX Series and EX Series allows an unauthenticated, network-based attacker to cause Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88124 [juniper.net] for more information.

Resolved In: junos:21.4R3-S7 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S2 junos:23.2R2-S1 junos:23.4R1-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1645119Junos OS and Junos OS Evolved: Confidential information in logs can be accessed by another user (CVE-2024-39532)
Product-Group=junos
An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information. Please refer to https://supportportal.juniper.net/JSA82992 [juniper.net] for more information.

Resolved In: evo:21.4X9-EVO evo:22.2R2-S1-EVO evo:22.2R3-EVO evo:22.3R1-S1-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:21.2R3-S9 junos:21.4R3-S9 junos:22.1R2-S2 junos:22.2R2-S1 junos:22.2R3 junos:22.3R1-S1 junos:22.3R1-S2 junos:22.3R2 junos:22.4R1 junos:22.4R2 junos:23.1R1 junos:23.2R2-S1

Modification History

First publication 2024-10-23