TROYANOSYVIRUS
Voltar para CVEs

CVE-2023-28984

MEDIUM
5.3

Descricao

A Use After Free vulnerability in the Layer 2 Address Learning Manager (l2alm) of Juniper Networks Junos OS on QFX Series allows an adjacent attacker to cause the Packet Forwarding Engine to crash and restart, leading to a Denial of Service (DoS). The PFE may crash when a lot of MAC learning and aging happens, but due to a Race Condition (Concurrent Execution using Shared Resource with Improper Synchronization) that is outside the attackers direct control. This issue affects: Juniper Networks Junos OS versions prior to 19.4R3-S10 on QFX Series; 20.2 versions prior to 20.2R3-S7 on QFX Series; 20.3 versions prior to 20.3R3-S6 on QFX Series; 20.4 versions prior to 20.4R3-S5 on QFX Series; 21.1 versions prior to 21.1R3-S4 on QFX Series; 21.2 versions prior to 21.2R3-S3 on QFX Series; 21.3 versions prior to 21.3R3-S3 on QFX Series; 21.4 versions prior to 21.4R3 on QFX Series; 22.1 versions prior to 22.1R3 on QFX Series; 22.2 versions prior to 22.2R2 on QFX Series.

Detalhes CVE

Pontuacao CVSS v3.15.3
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Vetor de ataqueADJACENT_NETWORK
ComplexidadeHIGH
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado4/17/2023
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0

Produtos afetados

juniper:junosjuniper:qfx10000juniper:qfx10002juniper:qfx10002-32qjuniper:qfx10002-60cjuniper:qfx10002-72qjuniper:qfx10008juniper:qfx10016juniper:qfx10kjuniper:qfx3000-gjuniper:qfx3000-mjuniper:qfx3008-ijuniper:qfx3100juniper:qfx3500juniper:qfx3600juniper:qfx3600-ijuniper:qfx5100juniper:qfx5100-96sjuniper:qfx5110juniper:qfx5120juniper:qfx5130juniper:qfx5200juniper:qfx5200-32cjuniper:qfx5200-48yjuniper:qfx5210juniper:qfx5210-64cjuniper:qfx5220

Fraquezas (CWE)

CWE-362CWE-416CWE-362CWE-416

Referencias

https://supportportal.juniper.net/JSA70610(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.