An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows an unauthenticated, network-based attacker to cause an integrity impact to networks downstream of the vulnerable device. When an output firewall filter is applied to an interface it doesn't recognize matching packets but permits any traffic. This issue affects Junos OS 21.4 releases from 21.4R1 earlier than 21.4R3-S6. This issue does not affect Junos OS releases earlier than 21.4R1.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XJuniper Ex4300
HWJuniperall versionsJuniper Ex4300 24p
HWJuniperall versionsJuniper Ex4300 24p S
HWJuniperall versionsJuniper Ex4300 24t
HWJuniperall versionsJuniper Ex4300 24t S
HWJuniperall versionsJuniper Ex4300 32f
HWJuniperall versionsJuniper Ex4300 32f Dc
HWJuniperall versionsJuniper Ex4300 32f S
HWJuniperall versionsJuniper Ex4300 48mp
HWJuniperall versionsJuniper Ex4300 48mp S
HWJuniperall versionsJuniper Ex4300 48p
HWJuniperall versionsJuniper Ex4300 48p S
HWJuniperall versionsJuniper Ex4300 48t
HWJuniperall versionsJuniper Ex4300 48t Afi
HWJuniperall versionsJuniper Ex4300 48t Dc
HWJuniperall versionsJuniper Ex4300 48t Dc Afi
HWJuniperall versionsJuniper Ex4300 48t S
HWJuniperall versionsJuniper Junos
OSJuniper21.4
Related vulnerabilities
RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)
Out-of-bounds Write w J-Web Juniper Junos OS — RCE z uprawnieniami root
Hard-coded Credentials w Juniper Junos OS na urządzeniach NFX Series
Buffer overflow w usłudze overlayd Juniper Junos OS — RCE i DoS
Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message