CVE-2023-44184Improper Restriction of Operations within the Bounds of a Memory Buffer in Networks Junos OS

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 66.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13

Description

An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the management daemon (mgd) process of Juniper Networks Junos OS and Junos OS Evolved allows a network-based authenticated low-privileged attacker, by executing a specific command via NETCONF, to cause a CPU Denial of Service to the device's control plane. This issue affects: Juniper Networks Junos OS * All versions prior to 20.4R3-S7; * 21.2 versions prior to 21.2R3-S5; * 21.3 versions prior to 21.3R

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5juniper_networks/junos_os_evolved22.122.1R3-S2-EVO+4
CVEListV5juniper_networks/junos_os21.121.1R1+8
NVDjuniper/junos< 20.4+8

🔴Vulnerability Details

2
GHSA
GHSA-c9pj-4j3g-856x: An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the management daemon (mgd) process of Juniper Networks Ju2023-10-13
CVEList
Junos OS and Junos OS Evolved: High CPU load due to specific NETCONF command2023-10-12

📋Vendor Advisories

1
Juniper
CVE-2023-44184: An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the management daemon (mgd) process of Juniper Networks J2023-10-13
CVE-2023-44184 — Networks Junos OS vulnerability | cvebase