CVE-2023-44185: Junos OS and Junos OS Evolved: In an BGP scenario RPD crashes upon receiving and processing a specific malformed ISO VPN BGP UPDATE packet
An Improper Input Validation vulnerability in the routing protocol daemon (rpd) of Juniper Networks allows an attacker to cause a Denial of Service (DoS )to the device upon receiving and processing a specific malformed ISO VPN BGP UPDATE packet.
Continued receipt of this packet will cause a sustained Denial of Service condition.
This issue affects:
Juniper Networks Junos OS: All versions prior to 20.4R3-S6; 21.1 versions prior to 21.1R3-S5; 21.2 versions prior to 21.2R3-S4; 21.3 versions prior to 21.3R3-S3; 21.4 versions prior to 21.4R3-S3; 22.1 versions prior to 22.1R2-S2, 22.1R3; 22.2 versions prior to 22.2R2-S1, 22.2R3; 22.3 versions prior to 22.3R1-S2, 22.3R2.
Juniper Networks Junos OS Evolved:
All versions prior to 20.4R3-S6-EVO; 21.1-EVO version 21.1R1-EVO and later versions prior to 21.2R3-S4-EVO; 21.3-EVO versions prior to 21.3R3-S3-EVO; 21.4-EVO versions prior to 21.4R3-S3-EVO; 22.1-EVO versions prior to 22.1R3-EVO; 22.2-EVO versions prior to 22.2R2-S1-EVO, 22.2R3-EVO; 22.3-EVO versions prior to 22.3R1-S2-EVO, 22.3R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44185?
CVE-2023-44185 is a critical vulnerability that can lead to a Denial of Service (DoS) condition on affected devices.
How do I fix CVE-2023-44185?
To mitigate CVE-2023-44185, it is recommended to update the affected Juniper Networks Junos software to the latest version provided by the vendor.
Which versions of Junos are affected by CVE-2023-44185?
CVE-2023-44185 affects Junos versions up to and including 20.4 and several 21.x and 22.x releases.
What type of vulnerability is CVE-2023-44185?
CVE-2023-44185 is classified as an Improper Input Validation vulnerability within the routing protocol daemon (rpd).
What impact does CVE-2023-44185 have on devices?
The impact of CVE-2023-44185 is that it allows attackers to disrupt the normal operation of the device, leading to a Denial of Service.