Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jgqx-5mhh-hg95

Опубликовано: 11 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to send specific RPKI-RTR packets resulting in a crash, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.

This issue affects 

Junos OS: 

  • All versions before 21.2R3-S8, 
  • from 21.4 before 21.4R3-S8,
  • from 22.2 before 22.2R3-S4, 
  • from 22.3 before 22.3R3-S3, 
  • from 22.4 before 22.4R3-S2, 
  • from 23.2 before 23.2R2-S1, 
  • from 23.4 before 23.4R2.

Junos OS Evolved: * All versions before 21.2R3-S8-EVO,

  • from 21.4 before 21.4R3-S8-EVO,
  • from 22.2 before 22.2R3-S4-EVO, 
  • from 22.3 before 22.3R3-S3-EVO,
  • from 22.4 before 22.4R3-S2-EVO, 
  • from 23.2 before 23.2R2-S1-EVO,
  • from 23.4 before 23.4R2-EVO.

A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to send specific RPKI-RTR packets resulting in a crash, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.

This issue affects 

Junos OS: 

  • All versions before 21.2R3-S8, 
  • from 21.4 before 21.4R3-S8,
  • from 22.2 before 22.2R3-S4, 
  • from 22.3 before 22.3R3-S3, 
  • from 22.4 before 22.4R3-S2, 
  • from 23.2 before 23.2R2-S1, 
  • from 23.4 before 23.4R2.

Junos OS Evolved: * All versions before 21.2R3-S8-EVO,

  • from 21.4 before 21.4R3-S8-EVO,
  • from 22.2 before 22.2R3-S4-EVO, 
  • from 22.3 before 22.3R3-S3-EVO,
  • from 22.4 before 22.4R3-S2-EVO, 
  • from 23.2 before 23.2R2-S1-EVO,
  • from 23.4 before 23.4R2-EVO.

EPSS

Процентиль: 36%
0.00148
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to send specific RPKI-RTR packets resulting in a crash, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue affects  Junos OS:  * All versions before 21.2R3-S8,  * from 21.4 before 21.4R3-S8, * from 22.2 before 22.2R3-S4,  * from 22.3 before 22.3R3-S3,  * from 22.4 before 22.4R3-S2,  * from 23.2 before 23.2R2-S1,  * from 23.4 before 23.4R2. Junos OS Evolved: * All versions before 21.2R3-S8-EVO, * from 21.4 before 21.4R3-S8-EVO, * from 22.2 before 22.2R3-S4-EVO,  * from 22.3 before 22.3R3-S3-EVO, * from 22.4 before 22.4R3-S2-EVO,  * from 23.2 before 23.2R2-S1-EVO, * from 23.4 before 23.4R2-EVO.

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость демона протокола маршрутизации (rpd) операционных систем Juniper Networks Junos OS и Junos OS Evolved, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 36%
0.00148
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-120