cbcvebase.
CVE-2023-44181
published 2023-10-13

CVE-2023-44181: An Improperly Implemented Security Check for Standard vulnerability in storm control of Juniper Networks Junos OS QFX5k devices allows packets to be punted to…

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.53%
41.3th percentile
An Improperly Implemented Security Check for Standard vulnerability in storm control of Juniper Networks Junos OS QFX5k devices allows packets to be punted to ARP queue causing a l2 loop resulting in a DDOS violations and DDOS syslog.

This issue is triggered when Storm control is enabled and ICMPv6 packets are present on device.

This issue affects Juniper Networks:

Junos OS


* All versions prior to 20.2R3-S6 on QFX5k;
* 20.3 versions prior to 20.3R3-S5 on QFX5k;
* 20.4 versions prior to 20.4R3-S5 on QFX5k;
* 21.1 versions prior to 21.1R3-S4 on QFX5k;
* 21.2 versions prior to 21.2R3-S3 on QFX5k;
* 21.3 versions prior to 21.3R3-S2 on QFX5k;
* 21.4 versions prior to 21.4R3 on QFX5k;
* 22.1 versions prior to 22.1R3 on QFX5k;
* 22.2 versions prior to 22.2R2 on QFX5k.

Affected

21 ranges
VendorProductVersion rangeFixed in
juniperjunos< 20.220.2
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos_os
juniperqfx_series
juniper_networksjunos_os< 20.2R3-S620.2R3-S6
juniper_networksjunos_os>= 20.3 < 20.3R3-S520.3R3-S5
juniper_networksjunos_os>= 20.4 < 20.4R3-S520.4R3-S5
juniper_networksjunos_os>= 21.1 < 21.1R3-S421.1R3-S4
juniper_networksjunos_os>= 21.2 < 21.2R3-S321.2R3-S3
juniper_networksjunos_os>= 21.3 < 21.3R3-S221.3R3-S2
juniper_networksjunos_os>= 21.4 < 21.4R321.4R3
juniper_networksjunos_os>= 22.1 < 22.1R322.1R3
juniper_networksjunos_os>= 22.2 < 22.2R222.2R2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.