CVE-2023-22412: Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash if the SIP ALG is enabled and specific SIP messages are processed
An Improper Locking vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC or MS-MIC card and SRX Series allows an unauthenticated, network-based attacker to cause a flow processing daemon (flowd) crash and thereby a Denial of Service (DoS). Continued receipt of these specific packets will cause a sustained Denial of Service condition. This issue occurs when SIP ALG is enabled and specific SIP messages are processed simultaneously. This issue affects: Juniper Networks Junos OS on MX Series and SRX Series 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S3; 21.2 versions prior to 21.2R3-S2; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R3; 22.1 versions prior to 22.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1 on MX Series, or SRX Series.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-22412?
The severity of CVE-2023-22412 is classified as high, allowing for potential Denial of Service attacks.
How do I fix CVE-2023-22412?
To fix CVE-2023-22412, update your Junos OS to the latest patched version as specified in the vendor's security advisory.
Which devices are affected by CVE-2023-22412?
CVE-2023-22412 affects Juniper Networks Junos OS on MX Series and SRX Series devices with specific hardware configurations.
Who is vulnerable to CVE-2023-22412?
Unauthenticated, network-based attackers can exploit CVE-2023-22412, leading to denial of service conditions on vulnerable devices.
Is there a workaround for CVE-2023-22412?
There are no official workarounds for CVE-2023-22412; upgrading to the latest version is the recommended course of action.