ID

VAR-202301-0903


CVE

CVE-2023-22406


TITLE

Juniper Networks Junos OS  and  Junos OS Evolved  Vulnerability regarding lack of memory release after expiration in

Trust: 0.8

sources: JVNDB: JVNDB-2023-001515

DESCRIPTION

A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). In a segment-routing scenario with OSPF as IGP, when a peer interface continuously flaps, next-hop churn will happen and a continuous increase in Routing Protocol Daemon (rpd) memory consumption will be observed. This will eventually lead to an rpd crash and restart when the memory is full. The memory consumption can be monitored using the CLI command "show task memory detail" as shown in the following example: user@host> show task memory detail | match "RT_NEXTHOPS_TEMPLATE|RT_TEMPLATE_BOOK_KEE" RT_NEXTHOPS_TEMPLATE 1008 1024 T 50 51200 50 51200 RT_NEXTHOPS_TEMPLATE 688 768 T 50 38400 50 38400 RT_NEXTHOPS_TEMPLATE 368 384 T 412330 158334720 412330 158334720 RT_TEMPLATE_BOOK_KEE 2064 2560 T 33315 85286400 33315 85286400 user@host> show task memory detail | match "RT_NEXTHOPS_TEMPLATE|RT_TEMPLATE_BOOK_KEE" RT_NEXTHOPS_TEMPLATE 1008 1024 T 50 51200 50 51200 RT_NEXTHOPS_TEMPLATE 688 768 T 50 38400 50 38400 RT_NEXTHOPS_TEMPLATE 368 384 T 419005 160897920 419005 160897920 <=== RT_TEMPLATE_BOOK_KEE 2064 2560 T 39975 102336000 39975 10233600 <=== This issue affects: Juniper Networks Junos OS All versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S8, 19.4R3-S9; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S3; 21.2 versions prior to 21.2R3-S2; 21.3 versions prior to 21.3R3-S1; 21.4 versions prior to 21.4R2-S1, 21.4R3; 22.1 versions prior to 22.1R2. Juniper Networks Junos OS Evolved All versions prior to 20.4R3-S4-EVO; 21.4 versions prior to 21.4R2-S1-EVO, 21.4R3-EVO; 22.1 versions prior to 22.1R2-EVO

Trust: 1.8

sources: NVD: CVE-2023-22406 // JVNDB: JVNDB-2023-001515 // VULHUB: VHN-449822 // VULMON: CVE-2023-22406

AFFECTED PRODUCTS

vendor:junipermodel:junosscope:eqversion:19.3

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:19.4

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:21.3

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:21.2

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:20.4

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:20.2

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:20.3

Trust: 1.0

vendor:junipermodel:junosscope:ltversion:19.3

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:22.1

Trust: 1.0

vendor:junipermodel:junos os evolvedscope:eqversion:20.4

Trust: 1.0

vendor:junipermodel:junos os evolvedscope:ltversion:20.4

Trust: 1.0

vendor:junipermodel:junos os evolvedscope:eqversion:22.1

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:21.4

Trust: 1.0

vendor:junipermodel:junosscope:eqversion:21.1

Trust: 1.0

vendor:junipermodel:junos os evolvedscope:eqversion:21.4

Trust: 1.0

vendor:ジュニパーネットワークスmodel:junos os evolvedscope: - version: -

Trust: 0.8

vendor:ジュニパーネットワークスmodel:junos osscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2023-001515 // NVD: CVE-2023-22406

CVSS

SEVERITY

CVSSV2

CVSSV3

sirt@juniper.net: CVE-2023-22406
value: MEDIUM

Trust: 1.0

OTHER: JVNDB-2023-001515
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202301-1032
value: MEDIUM

Trust: 0.6

sirt@juniper.net: CVE-2023-22406
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

OTHER: JVNDB-2023-001515
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2023-001515 // CNNVD: CNNVD-202301-1032 // NVD: CVE-2023-22406

PROBLEMTYPE DATA

problemtype:CWE-401

Trust: 1.1

problemtype:Lack of memory release after expiration (CWE-401) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-449822 // JVNDB: JVNDB-2023-001515 // NVD: CVE-2023-22406

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202301-1032

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202301-1032

PATCH

title:JSA70202url:https://kb.juniper.net/JSA70202

Trust: 0.8

title:Juniper Networks Junos OS Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=221272

Trust: 0.6

title: - url:https://github.com/Live-Hack-CVE/CVE-2023-22406

Trust: 0.1

sources: VULMON: CVE-2023-22406 // JVNDB: JVNDB-2023-001515 // CNNVD: CNNVD-202301-1032

EXTERNAL IDS

db:NVDid:CVE-2023-22406

Trust: 3.4

db:JUNIPERid:JSA70202

Trust: 1.8

db:JVNDBid:JVNDB-2023-001515

Trust: 0.8

db:CNNVDid:CNNVD-202301-1032

Trust: 0.6

db:VULHUBid:VHN-449822

Trust: 0.1

db:VULMONid:CVE-2023-22406

Trust: 0.1

sources: VULHUB: VHN-449822 // VULMON: CVE-2023-22406 // JVNDB: JVNDB-2023-001515 // CNNVD: CNNVD-202301-1032 // NVD: CVE-2023-22406

REFERENCES

url:https://kb.juniper.net/jsa70202

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2023-22406

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2023-22406/

Trust: 0.6

url:https://github.com/live-hack-cve/cve-2023-22406

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-449822 // VULMON: CVE-2023-22406 // JVNDB: JVNDB-2023-001515 // CNNVD: CNNVD-202301-1032 // NVD: CVE-2023-22406

SOURCES

db:VULHUBid:VHN-449822
db:VULMONid:CVE-2023-22406
db:JVNDBid:JVNDB-2023-001515
db:CNNVDid:CNNVD-202301-1032
db:NVDid:CVE-2023-22406

LAST UPDATE DATE

2024-08-14T15:05:56.740000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-449822date:2023-01-24T00:00:00
db:VULMONid:CVE-2023-22406date:2023-01-13T00:00:00
db:JVNDBid:JVNDB-2023-001515date:2023-04-17T02:52:00
db:CNNVDid:CNNVD-202301-1032date:2023-01-28T00:00:00
db:NVDid:CVE-2023-22406date:2023-01-24T18:33:08.510

SOURCES RELEASE DATE

db:VULHUBid:VHN-449822date:2023-01-13T00:00:00
db:VULMONid:CVE-2023-22406date:2023-01-13T00:00:00
db:JVNDBid:JVNDB-2023-001515date:2023-04-17T00:00:00
db:CNNVDid:CNNVD-202301-1032date:2023-01-13T00:00:00
db:NVDid:CVE-2023-22406date:2023-01-13T00:15:10.990