CVE-2023-36832: Junos OS: MX Series: PFE crash upon receipt of specific packet destined to an AMS interface
An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) interface on the device, causing the packet forwarding engine (PFE) to crash, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.
This issue is only triggered by packets destined to a local-interface via a service-interface (AMS). AMS is only supported on the MS-MPC, MS-MIC, and MX-SPC3 cards. This issue is not experienced on other types of interfaces or configurations. Additionally, transit traffic does not trigger this issue.
This issue affects Juniper Networks Junos OS on MX Series: All versions prior to 19.1R3-S10; 19.2 versions prior to 19.2R3-S7; 19.3 versions prior to 19.3R3-S8; 19.4 versions prior to 19.4R3-S12; 20.2 versions prior to 20.2R3-S8; 20.4 versions prior to 20.4R3-S7; 21.1 versions prior to 21.1R3-S5; 21.2 versions prior to 21.2R3-S5; 21.3 versions prior to 21.3R3-S4; 21.4 versions prior to 21.4R3-S3; 22.1 versions prior to 22.1R3-S2; 22.2 versions prior to 22.2R3; 22.3 versions prior to 22.3R2-S1, 22.3R3; 22.4 versions prior to 22.4R1-S2, 22.4R2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 19.1R3-S10 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 19.2R3-S7 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 19.3R3-S8 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 19.4R3-S12 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 20.2R3-S8 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 20.4R3-S7 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 21.1R3-S5 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 21.2R3-S5 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 21.3R3-S4 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 21.4R3-S3 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 22.1R3-S2 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 22.2R3 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 22.3R2-S1 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 22.3R3 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 22.4R1-S2 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 22.4R2 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series)to a version that resolves this vulnerability.Fixed in 23.1R1
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36832?
The severity of CVE-2023-36832 is classified as high due to the potential impact of unauthenticated access to vulnerable devices.
How do I fix CVE-2023-36832?
To fix CVE-2023-36832, you should update Juniper Networks Junos OS to the latest version that addresses this vulnerability.
What types of devices are affected by CVE-2023-36832?
CVE-2023-36832 affects various Juniper Networks MX Series devices running specific versions of Junos OS.
What are the implications of CVE-2023-36832?
The implications of CVE-2023-36832 include the risk of denial of service and potential unauthorized access to network traffic if exploited.
Is there a patch available for CVE-2023-36832?
Yes, a patch for CVE-2023-36832 is available, and it is recommended to apply it at your earliest convenience.