HIGH🇵🇱 Wersja polska

CVE-2023-22394

CVSS 7.5v3.1pub. 2023-01-13upd. 2024-11-21

An Improper Handling of Unexpected Data Type vulnerability in the handling of SIP calls in Juniper Networks Junos OS on SRX Series and MX Series platforms allows an attacker to cause a memory leak leading to Denial of Services (DoS). This issue occurs on all MX Series platforms with MS-MPC or MS-MIC card and all SRX Series platforms where SIP ALG is enabled. Successful exploitation of this vulnerability prevents additional SIP calls and applications from succeeding. The SIP ALG needs to be enabled, either implicitly / by default or by way of configuration. To confirm whether SIP ALG is enabled on SRX use the following command: user@host> show security alg status | match sip SIP : Enabled This issue affects Juniper Networks Junos OS on SRX Series and on MX Series: All versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S8, 19.4R3-S10; 20.1 versions 20.1R1 and later versions; 20.2 versions prior to 20.2R3-S6; 20.3 versions prior to 20.3R3-S6; 20.4 versions prior to 20.4R3-S5; 21.1 versions prior to 21.1R3-S5; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R2-S2, 21.4R3; 22.1 versions prior to 22.1R1-S2, 22.1R2, 22.1R3-S1. This issue does not affect Juniper Networks Junos OS on SRX Series and on MX Series: All versions prior to 18.2R1.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Juniper Junos

    OS
    Juniper
    19.319.420.120.220.320.421.121.221.321.422.1< 19.3
  • Juniper Mx10

    HW
    Juniper
    all versions
  • Juniper Mx10000

    HW
    Juniper
    all versions
  • Juniper Mx10003

    HW
    Juniper
    all versions
  • Juniper Mx10008

    HW
    Juniper
    all versions
  • Juniper Mx10016

    HW
    Juniper
    all versions
  • Juniper Mx104

    HW
    Juniper
    all versions
  • Juniper Mx150

    HW
    Juniper
    all versions
  • Juniper Mx2008

    HW
    Juniper
    all versions
  • Juniper Mx2010

    HW
    Juniper
    all versions
  • Juniper Mx2020

    HW
    Juniper
    all versions
  • Juniper Mx204

    HW
    Juniper
    all versions
  • Juniper Mx240

    HW
    Juniper
    all versions
  • Juniper Mx40

    HW
    Juniper
    all versions
  • Juniper Mx480

    HW
    Juniper
    all versions
  • Juniper Mx5

    HW
    Juniper
    all versions
  • Juniper Mx80

    HW
    Juniper
    all versions
  • Juniper Mx960

    HW
    Juniper
    all versions
  • Juniper Srx100

    HW
    Juniper
    all versions
  • Juniper Srx110

    HW
    Juniper
    all versions
  • Juniper Srx1400

    HW
    Juniper
    all versions
  • Juniper Srx1500

    HW
    Juniper
    all versions
  • Juniper Srx210

    HW
    Juniper
    all versions
  • Juniper Srx220

    HW
    Juniper
    all versions
  • Juniper Srx240

    HW
    Juniper
    all versions
  • Juniper Srx240h2

    HW
    Juniper
    all versions
  • Juniper Srx240m

    HW
    Juniper
    all versions
  • Juniper Srx300

    HW
    Juniper
    all versions
  • Juniper Srx320

    HW
    Juniper
    all versions
  • Juniper Srx340

    HW
    Juniper
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2023-36845CRITICAL9.8⚠ KEVPL ✓same product

RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)

CVE-2024-21591CRITICAL9.8PL ✓same product

Out-of-bounds Write w J-Web Juniper Junos OS — RCE z uprawnieniami root

CVE-2021-0248CRITICAL10.0PL ✓same product

Hard-coded Credentials w Juniper Junos OS na urządzeniach NFX Series

CVE-2021-0254CRITICAL9.8PL ✓same product

Buffer overflow w usłudze overlayd Juniper Junos OS — RCE i DoS

CVE-2021-0211CRITICAL10.0PL ✓same product

Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message