CVE-2023-22416: Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash if SIP ALG is enabled and a malformed SIP packet is received
A Buffer Overflow vulnerability in SIP ALG of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). On all MX Series and SRX Series platform with SIP ALG enabled, when a malformed SIP packet is received, the flow processing daemon (flowd) will crash and restart. This issue affects: Juniper Networks Junos OS on MX Series and SRX Series 20.4 versions prior to 20.4R3-S5; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S2; 21.3 versions prior to 21.3R3-S1; 21.4 versions prior to 21.4R3; 22.1 versions prior to 22.1R1-S2, 22.1R2; 22.2 versions prior to 22.2R1-S1, 22.2R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1 on SRX Series.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-22416?
CVE-2023-22416 is classified as a high-severity vulnerability due to its ability to cause a Denial of Service (DoS).
How do I fix CVE-2023-22416?
To mitigate CVE-2023-22416, it is recommended to disable SIP ALG or upgrade to the latest version of Junos OS that addresses the vulnerability.
What are the affected versions related to CVE-2023-22416?
CVE-2023-22416 affects multiple versions of Juniper Networks Junos OS, including versions up to 20.4 and specific releases of 21.1 through 22.1.
Can CVE-2023-22416 be exploited remotely?
Yes, CVE-2023-22416 can be exploited remotely by an unauthenticated attacker through malformed SIP packets.
What devices are affected by CVE-2023-22416?
CVE-2023-22416 impacts all MX Series and SRX Series platforms with SIP ALG enabled.