Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x368-w88j-3c3r

Опубликовано: 12 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.8

Описание

An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows an unauthenticated, network-based attacker to cause an integrity impact to networks downstream of the vulnerable device.

When an output firewall filter is applied to an interface it doesn't recognize matching packets but permits any traffic. This issue affects Junos OS 21.4 releases from 21.4R1 earlier than 21.4R3-S6. This issue does not affect Junos OS releases earlier than 21.4R1.

An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows an unauthenticated, network-based attacker to cause an integrity impact to networks downstream of the vulnerable device.

When an output firewall filter is applied to an interface it doesn't recognize matching packets but permits any traffic. This issue affects Junos OS 21.4 releases from 21.4R1 earlier than 21.4R3-S6. This issue does not affect Junos OS releases earlier than 21.4R1.

EPSS

Процентиль: 38%
0.00162
Низкий

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-696

Связанные уязвимости

CVSS3: 5.8
nvd
почти 2 года назад

An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows an unauthenticated, network-based attacker to cause an integrity impact to networks downstream of the vulnerable device. When an output firewall filter is applied to an interface it doesn't recognize matching packets but permits any traffic. This issue affects Junos OS 21.4 releases from 21.4R1 earlier than 21.4R3-S6. This issue does not affect Junos OS releases earlier than 21.4R1.

CVSS3: 5.8
fstec
почти 2 года назад

Уязвимость модуля Packet Forwarding Engine (PFE) операционной системы Juniper Networks Junos OS сетевых устройств серии EX4300, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 38%
0.00162
Низкий

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-696