cbcvebase.
CVE-2023-22407
published 2023-01-13

CVE-2023-22407: An Incomplete Cleanup vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated…

PriorityP429medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.31%
22.9th percentile
An Incomplete Cleanup vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). An rpd crash can occur when an MPLS TE tunnel configuration change occurs on a directly connected router. This issue affects: Juniper Networks Junos OS All versions prior to 18.4R2-S7; 19.1 versions prior to 19.1R3-S2; 19.2 versions prior to 19.2R3; 19.3 versions prior to 19.3R3; 19.4 versions prior to 19.4R3; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R2. Juniper Networks Junos OS Evolved All versions prior to 19.2R3-EVO; 19.3 versions prior to 19.3R3-EVO; 19.4 versions prior to 19.4R3-EVO; 20.1 versions prior to 20.1R3-EVO; 20.2 versions prior to 20.2R2-EVO.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
juniperjunos< 18.418.4
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos_os
juniperjunos_os_evolved< 19.219.2
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniper_networksjunos_os>= 19.1 < 19.1R3-S219.1R3-S2
juniper_networksjunos_os>= 19.2 < 19.2R319.2R3
juniper_networksjunos_os>= 19.3 < 19.3R319.3R3
juniper_networksjunos_os>= 19.4 < 19.4R319.4R3
juniper_networksjunos_os>= 20.1 < 20.1R220.1R2
juniper_networksjunos_os>= 20.2 < 20.2R220.2R2
juniper_networksjunos_os>= unspecified < 18.4R2-S718.4R2-S7
juniper_networksjunos_os_evolved>= 19.3 < 19.3R3-EVO19.3R3-EVO
juniper_networksjunos_os_evolved>= 19.4 < 19.4R3-EVO19.4R3-EVO
juniper_networksjunos_os_evolved>= 20.1 < 20.1R3-EVO20.1R3-EVO
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.