CVE-2023-44203: Junos OS: QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600: Packet flooding will occur when IGMP traffic is sent to an isolated VLAN
An Improper Check or Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600 allows a adjacent attacker to send specific traffic, which leads to packet flooding, resulting in a Denial of Service (DoS).
When a specific IGMP packet is received in an isolated VLAN, it is duplicated to all other ports under the primary VLAN, which causes a flood.
This issue affects QFX5000 series, EX2300, EX3400, EX4100, EX4400 and EX4600 platforms only.
This issue affects Juniper Junos OS on on QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600:
All versions prior to 20.4R3-S5; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S3; 21.3 versions prior to 21.3R3-S5; 21.4 versions prior to 21.4R3-S2; 22.1 versions prior to 22.1R3; 22.2 versions prior to 22.2R3; 22.3 versions prior to 22.3R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44203?
CVE-2023-44203 is rated as a high severity vulnerability due to its potential to allow packet flooding by an adjacent attacker.
How do I fix CVE-2023-44203?
To remediate CVE-2023-44203, update your Junos OS to a version that addresses this vulnerability.
Which devices are affected by CVE-2023-44203?
CVE-2023-44203 affects Juniper Networks JUNOS on QFX5000 Series, EX2300, EX3400, EX4100, EX4400, and EX4600 devices.
Can CVE-2023-44203 be exploited remotely?
CVE-2023-44203 requires an adjacent attacker, meaning it cannot be exploited remotely without physical access.
What are the potential impacts of CVE-2023-44203?
The main impact of CVE-2023-44203 is packet flooding, which could lead to service disruptions.