cbcvebase.
CVE-2023-28974
published 2023-04-17

CVE-2023-28974: An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker…

medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). In a Broadband Edge / Subscriber Management scenario on MX Series when a specifically malformed ICMP packet addressed to the device is received from a subscriber the bbe-smgd will crash, affecting the subscriber sessions that are connecting, updating, or terminating. Continued receipt of such packets will lead to a sustained DoS condition. When this issue happens the below log can be seen if the traceoptions for the processes smg-service are enabled: BBE_TRACE(TRACE_LEVEL_INFO, "%s: Dropped unsupported ICMP PKT ... This issue affects Juniper Networks Junos OS on MX Series: All versions prior to 19.4R3-S11; 20.2 versions prior to 20.2R3-S7; 20.3 versions prior to 20.3R3-S6; 20.4 versions prior to 20.4R3-S6; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S4; 21.3 versions prior to 21.3R3-S3; 21.4 versions prior to 21.4R3-S2; 22.1 versions prior to 22.1R2-S2, 22.1R3; 22.2 versions prior to 22.2R2; 22.3 versions prior to 22.3R1-S2, 22.3R2.

Affected

24 ranges
VendorProductVersion rangeFixed in
juniperjunos< 19.419.4
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos_os
junipermx_series
juniper_networksjunos_os>= 20.2 < 20.2R3-S720.2R3-S7
juniper_networksjunos_os>= 20.3 < 20.3R3-S620.3R3-S6
juniper_networksjunos_os>= 20.4 < 20.4R3-S620.4R3-S6
juniper_networksjunos_os>= 21.1 < 21.1R3-S421.1R3-S4
juniper_networksjunos_os>= 21.2 < 21.2R3-S421.2R3-S4
juniper_networksjunos_os>= 21.3 < 21.3R3-S321.3R3-S3
juniper_networksjunos_os>= 21.4 < 21.4R3-S221.4R3-S2
juniper_networksjunos_os>= 22.1 < 22.1R2-S2, 22.1R322.1R2-S2, 22.1R3
juniper_networksjunos_os>= 22.2 < 22.2R222.2R2
juniper_networksjunos_os>= 22.3 < 22.3R1-S2, 22.3R222.3R1-S2, 22.3R2
juniper_networksjunos_os>= unspecified < 19.4R3-S1119.4R3-S11