CVE-2023-44204: Junos OS and Junos OS Evolved: The rpd will crash upon receiving a malformed BGP UPDATE message
An Improper Validation of Syntactic Correctness of Input vulnerability in Routing Protocol Daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS).
When a malformed BGP UPDATE packet is received over an established BGP session, the rpd crashes and restarts.
This issue affects both eBGP and iBGP implementations.
This issue affects:
Juniper Networks Junos OS
21.4 versions prior to 21.4R3-S4; 22.1 versions prior to 22.1R3-S3; 22.2 versions prior to 22.2R3-S2; 22.3 versions prior to 22.3R2-S2, 22.3R3; 22.4 versions prior to 22.4R2-S1, 22.4R3; 23.2 versions prior to 23.2R1, 23.2R2;
Juniper Networks Junos OS Evolved
21.4 versions prior to 21.4R3-S5-EVO; 22.1 versions prior to 22.1R3-S3-EVO; 22.2 versions prior to 22.2R3-S3-EVO; 22.3 versions prior to 22.3R2-S2-EVO; 22.4 versions prior to 22.4R3-EVO; 23.2 versions prior to 23.2R2-EVO;
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44204?
CVE-2023-44204 is classified as a high severity vulnerability due to its potential to cause a Denial of Service (DoS).
How do I fix CVE-2023-44204?
To fix CVE-2023-44204, you should upgrade your Juniper Networks Junos OS or Junos OS Evolved to the latest patched version.
Who can exploit CVE-2023-44204?
CVE-2023-44204 can be exploited by unauthenticated, network-based attackers.
What types of devices are affected by CVE-2023-44204?
CVE-2023-44204 affects various versions of Juniper Networks Junos OS and Junos OS Evolved, specifically those listed in the vulnerability report.
What impact does CVE-2023-44204 have on systems?
The impact of CVE-2023-44204 can lead to service disruption due to the Denial of Service (DoS) it can inflict on affected systems.