Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43mx-p8wf-wh27

Опубликовано: 11 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS Evolved on QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).

Several configuration statements meant to enforce limits on MAC learning and moves can be configured but do not take effect. This can lead to control plane overload situations which will severely impact the ability of the device to processes legitimate traffic.

This issue affects Junos OS Evolved on QFX5000 Series:

  • All versions before 21.4R3-S8-EVO,

  • 22.2-EVO versions before 22.2R3-S5-EVO,

  • 22.4-EVO versions before 22.4R3-EVO,

  • 23.2-EVO versions before 23.2R2-EVO.

An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS Evolved on QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).

Several configuration statements meant to enforce limits on MAC learning and moves can be configured but do not take effect. This can lead to control plane overload situations which will severely impact the ability of the device to processes legitimate traffic.

This issue affects Junos OS Evolved on QFX5000 Series:

  • All versions before 21.4R3-S8-EVO,

  • 22.2-EVO versions before 22.2R3-S5-EVO,

  • 22.4-EVO versions before 22.4R3-EVO,

  • 23.2-EVO versions before 23.2R2-EVO.

EPSS

Процентиль: 36%
0.00149
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS Evolved on QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Several configuration statements meant to enforce limits on MAC learning and moves can be configured but do not take effect. This can lead to control plane overload situations which will severely impact the ability of the device to processes legitimate traffic. This issue affects Junos OS Evolved on QFX5000 Series: * All versions before 21.4R3-S8-EVO, * 22.2-EVO versions before 22.2R3-S5-EVO, * 22.4-EVO versions before 22.4R3-EVO, * 23.2-EVO versions before 23.2R2-EVO.

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость интерфейса командной строки (CLI) операционной системы Junos OS Evolved маршрутизаторов QFX5000, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 36%
0.00149
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3