CVE-2023-44197

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 13, 2023
Updated: Oct 20, 2023
CWE ID 787

Summary

CVE-2023-44197 is a newly disclosed Out-of-Bounds Write vulnerability affecting the Routing Protocol Daemon (rpd) in Juniper Networks Junos OS and Junos OS Evolved. This issue permits unauthenticated, network-based attackers to cause a Denial of Service (DoS) by triggering an rpd crash and restart while processing BGP route updates. This vulnerability specifically impacts devices with BGP import policies configuring hundreds of terms matching IPv4 and IPv6 prefixes. Affected versions of Juniper Networks Junos OS include all versions prior to 20.4R3-S8, 21.1, 21.2 versions prior to 21.2R3-S2, 21.3 versions prior to 21.3R3-S5, and 21.4 versions prior to 21.4R2-S1 and 21.4R3-S5. Juniper Networks Junos OS Evolved versions also face the same vulnerability, with all versions prior to 20.4R3-S8-EVO, 21.1-EVO, 21.2-EVO versions prior to 21.2R3-S2-EVO, 21.3-EVO version 21.3R1-EVO, and 21.4-EVO versions prior to 21.4R2-S1-EVO and 21.4R3-S5-EVO being impacted.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share