CVE-2023-44191: Junos OS: QFX5000 Series and EX4000 Series: Denial of Service (DoS) on a large scale VLAN due to PFE hogging
An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).
On all Junos OS QFX5000 Series and EX4000 Series platforms, when a high number of VLANs are configured, a specific DHCP packet will cause PFE hogging which will lead to dropping of socket connections.
This issue affects:
Juniper Networks Junos OS on QFX5000 Series and EX4000 Series
21.1 versions prior to 21.1R3-S5; 21.2 versions prior to 21.2R3-S5; 21.3 versions prior to 21.3R3-S5; 21.4 versions prior to 21.4R3-S4; 22.1 versions prior to 22.1R3-S3; 22.2 versions prior to 22.2R3-S1; 22.3 versions prior to 22.3R2-S2, 22.3R3; 22.4 versions prior to 22.4R2.
This issue does not affect Juniper Networks Junos OS versions prior to 21.1R1
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44191?
CVE-2023-44191 is classified as a Denial of Service vulnerability in Juniper Networks Junos OS.
How can I fix CVE-2023-44191?
To mitigate CVE-2023-44191, users should apply the relevant security updates provided by Juniper Networks for affected systems.
Which products are affected by CVE-2023-44191?
CVE-2023-44191 affects Juniper Networks Junos OS on the QFX5000 Series and EX4000 Series platforms.
What attack vector does CVE-2023-44191 use?
CVE-2023-44191 can be exploited by an unauthenticated, network-based attacker.
What impact does CVE-2023-44191 have on systems?
Exploitation of CVE-2023-44191 can lead to a Denial of Service, rendering the affected device unresponsive.