CVE-2023-44191Allocation of Resources Without Limits or Throttling in Networks Junos OS

Severity
7.5HIGHNVD
EPSS
0.1%
top 68.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13

Description

An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all Junos OS QFX5000 Series and EX4000 Series platforms, when a high number of VLANs are configured, a specific DHCP packet will cause PFE hogging which will lead to dropping of socket connections. This issue affects: Juniper Networks Junos OS on QFX5000 Series and EX4000 Series * 21.1 versions prior to 21.1

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5juniper_networks/junos_os21.121.1R3-S5+7
NVDjuniper/junos8 versions+7

🔴Vulnerability Details

2
GHSA
GHSA-gg84-68cr-5wgm: An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker t2023-10-13
CVEList
Junos OS: QFX5000 Series and EX4000 Series: Denial of Service (DoS) on a large scale VLAN due to PFE hogging2023-10-12

📋Vendor Advisories

1
Juniper
CVE-2023-44191: An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker2023-10-13
CVE-2023-44191 — Networks Junos OS vulnerability | cvebase