CVE-2023-22403
published 2023-01-13CVE-2023-22403: An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.64%
46.7th percentile
An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).
On QFX10K Series, Inter-Chassis Control Protocol (ICCP) is used in MC-LAG topologies to exchange control information between the devices in the topology. ICCP connection flaps and sync issues will be observed due to excessive specific traffic to the local device.
This issue affects Juniper Networks Junos OS on QFX10K Series:
* All versions prior to 20.2R3-S7;
* 20.4 versions prior to 20.4R3-S4;
* 21.1 versions prior to 21.1R3-S3;
* 21.2 versions prior to 21.2R3-S1;
* 21.3 versions prior to 21.3R3;
* 21.4 versions prior to 21.4R3;
* 22.1 versions prior to 22.1R2.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | < 20.2 | 20.2 |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper | qfx_series | — | — |
| juniper_networks | junos_os | >= 20.4 < 20.4R3-S4 | 20.4R3-S4 |
| juniper_networks | junos_os | >= 21.1 < 21.1R3-S3 | 21.1R3-S3 |
| juniper_networks | junos_os | >= 21.2 < 21.2R3-S1 | 21.2R3-S1 |
| juniper_networks | junos_os | >= 21.3 < 21.3R3 | 21.3R3 |
| juniper_networks | junos_os | >= 21.4 < 21.4R3 | 21.4R3 |
| juniper_networks | junos_os | >= 22.1 < 22.1R2 | 22.1R2 |
| juniper_networks | junos_os | >= unspecified < 20.2R3-S7 | 20.2R3-S7 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Juniper
CVE-2023-22403:
An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a net
vendor_juniper·2023-01-13·CVSS 7.5
CVE-2023-22403 [HIGH] CWE-770 CVE-2023-22403:
An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a net
CVE-2023-22403:
An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).
On QFX10K Series, Inter-Chassis Control Protocol (ICCP) is used in MC-LAG topologies to exchange control information between the devices in the topology. ICCP connection flaps and sync issues will be observed due to excessive specific traffic to the local device.
This issue affects Juniper Networks Junos OS on QFX10K Series:
* All versions prior to 20.2R3-S7;
* 20.4 versions prior to 20.4R3-S4;
* 21.1 versions prior to 21.1R3-S3;
* 21.2 versions prior to 21.2R3-S1;
* 21.3 versions prior to 21.3R3;
* 21.4 versions prior to 21.4R3;
* 22.1 versions prior
GHSA
GHSA-2gch-6fpv-fjxp: An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a netw
ghsa_unreviewed·2023-01-13
CVE-2023-22403 [HIGH] CWE-770 GHSA-2gch-6fpv-fjxp: An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a netw
An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). On QFX10k Series Inter-Chassis Control Protocol (ICCP) is used in MC-LAG topologies to exchange control information between the devices in the topology. ICCP connection flaps and sync issues will be observed due to excessive specific traffic to the local device. This issue affects Juniper Networks Junos OS: All versions prior to 20.2R3-S7; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S3; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R3; 22.1 versions prior to 22.1R2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-13
Published