CVE-2023-36838

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jul 14, 2023
Updated: Jul 27, 2023
CWE ID 125

Summary

CVE-2023-36838 is a local Denial of Service (DoS) vulnerability affecting Juniper Networks Junos OS on SRX Series. An authenticated, low-privileged user can cause the flow processing daemon (flowd) to crash by executing a specific command. This results in a temporary traffic interruption until the process is restarted automatically. Repeated execution of this command can lead to a sustained DoS. This issue affects several versions of Junos OS on SRX Series, including all versions prior to 20.2R3-S7, 20.3R1 and later versions, 20.4 versions prior to 20.4R3-S6, 21.1 versions prior to 21.1R3-S5, 21.2 versions prior to 21.2R3-S4, 21.3 versions prior to 21.3R3-S4, 21.4 versions prior to 21.4R3-S3, 22.1 versions prior to 22.1R3-S1, 22.2 versions prior to 22.2R3, 22.3 versions prior to 22.3R2, and 22.4 versions prior to 22.4R1-S1 and 22.4R2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share