CVE-2023-22415Out-of-bounds Write in Networks Junos OS

Severity
7.5HIGHNVD
EPSS
0.5%
top 34.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13

Description

An Out-of-Bounds Write vulnerability in the H.323 ALG of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all MX Series and SRX Series platform, when H.323 ALG is enabled and specific H.323 packets are received simultaneously, a flow processing daemon (flowd) crash will occur. Continued receipt of these specific packets will cause a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS on MX Seri

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5juniper_networks/junos_osunspecified19.4R3-S10+9
NVDjuniper/junos< 19.4+10

🔴Vulnerability Details

2
GHSA
GHSA-w9qx-xcjf-3922: An Out-of-Bounds Write vulnerability in the H2023-01-13
CVEList
Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash when specific H.323 packets are received2023-01-12

📋Vendor Advisories

1
Juniper
CVE-2023-22415: An Out-of-Bounds Write vulnerability in the H.323 ALG of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial o2023-01-13
CVE-2023-22415 — Out-of-bounds Write | cvebase