CVE Vulnerabilities

CVE-2023-22407

Incomplete Cleanup

Published: Jan 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An Incomplete Cleanup vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). An rpd crash can occur when an MPLS TE tunnel configuration change occurs on a directly connected router. This issue affects: Juniper Networks Junos OS All versions prior to 18.4R2-S7; 19.1 versions prior to 19.1R3-S2; 19.2 versions prior to 19.2R3; 19.3 versions prior to 19.3R3; 19.4 versions prior to 19.4R3; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R2. Juniper Networks Junos OS Evolved All versions prior to 19.2R3-EVO; 19.3 versions prior to 19.3R3-EVO; 19.4 versions prior to 19.4R3-EVO; 20.1 versions prior to 20.1R3-EVO; 20.2 versions prior to 20.2R2-EVO.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

NameVendorStart VersionEnd Version
JunosJuniper*18.4 (excluding)
JunosJuniper18.4 (including)18.4 (including)
JunosJuniper18.4-r1 (including)18.4-r1 (including)
JunosJuniper18.4-r1-s1 (including)18.4-r1-s1 (including)
JunosJuniper18.4-r1-s2 (including)18.4-r1-s2 (including)
JunosJuniper18.4-r1-s3 (including)18.4-r1-s3 (including)
JunosJuniper18.4-r1-s4 (including)18.4-r1-s4 (including)
JunosJuniper18.4-r1-s5 (including)18.4-r1-s5 (including)
JunosJuniper18.4-r1-s6 (including)18.4-r1-s6 (including)
JunosJuniper18.4-r1-s7 (including)18.4-r1-s7 (including)
JunosJuniper18.4-r2 (including)18.4-r2 (including)
JunosJuniper18.4-r2-s1 (including)18.4-r2-s1 (including)
JunosJuniper18.4-r2-s10 (including)18.4-r2-s10 (including)
JunosJuniper18.4-r2-s2 (including)18.4-r2-s2 (including)
JunosJuniper18.4-r2-s3 (including)18.4-r2-s3 (including)
JunosJuniper18.4-r2-s4 (including)18.4-r2-s4 (including)
JunosJuniper18.4-r2-s5 (including)18.4-r2-s5 (including)
JunosJuniper18.4-r2-s6 (including)18.4-r2-s6 (including)
JunosJuniper19.1 (including)19.1 (including)
JunosJuniper19.1-r1 (including)19.1-r1 (including)
JunosJuniper19.1-r1-s1 (including)19.1-r1-s1 (including)
JunosJuniper19.1-r1-s2 (including)19.1-r1-s2 (including)
JunosJuniper19.1-r1-s3 (including)19.1-r1-s3 (including)
JunosJuniper19.1-r1-s4 (including)19.1-r1-s4 (including)
JunosJuniper19.1-r1-s5 (including)19.1-r1-s5 (including)
JunosJuniper19.1-r1-s6 (including)19.1-r1-s6 (including)
JunosJuniper19.1-r2 (including)19.1-r2 (including)
JunosJuniper19.1-r2-s1 (including)19.1-r2-s1 (including)
JunosJuniper19.1-r2-s2 (including)19.1-r2-s2 (including)
JunosJuniper19.1-r2-s3 (including)19.1-r2-s3 (including)
JunosJuniper19.1-r3 (including)19.1-r3 (including)
JunosJuniper19.1-r3-s1 (including)19.1-r3-s1 (including)
JunosJuniper19.2 (including)19.2 (including)
JunosJuniper19.2-r1 (including)19.2-r1 (including)
JunosJuniper19.2-r1-s1 (including)19.2-r1-s1 (including)
JunosJuniper19.2-r1-s2 (including)19.2-r1-s2 (including)
JunosJuniper19.2-r1-s3 (including)19.2-r1-s3 (including)
JunosJuniper19.2-r1-s4 (including)19.2-r1-s4 (including)
JunosJuniper19.2-r1-s5 (including)19.2-r1-s5 (including)
JunosJuniper19.2-r1-s6 (including)19.2-r1-s6 (including)
JunosJuniper19.2-r1-s7 (including)19.2-r1-s7 (including)
JunosJuniper19.2-r1-s8 (including)19.2-r1-s8 (including)
JunosJuniper19.2-r1-s9 (including)19.2-r1-s9 (including)
JunosJuniper19.2-r2 (including)19.2-r2 (including)
JunosJuniper19.2-r2-s1 (including)19.2-r2-s1 (including)
JunosJuniper19.2-r3 (including)19.2-r3 (including)
JunosJuniper19.2-r3-s1 (including)19.2-r3-s1 (including)
JunosJuniper19.3 (including)19.3 (including)
JunosJuniper19.3-r1 (including)19.3-r1 (including)
JunosJuniper19.3-r1-s1 (including)19.3-r1-s1 (including)
JunosJuniper19.3-r2 (including)19.3-r2 (including)
JunosJuniper19.3-r2-s1 (including)19.3-r2-s1 (including)
JunosJuniper19.3-r2-s2 (including)19.3-r2-s2 (including)
JunosJuniper19.3-r2-s3 (including)19.3-r2-s3 (including)
JunosJuniper19.3-r2-s4 (including)19.3-r2-s4 (including)
JunosJuniper19.3-r2-s5 (including)19.3-r2-s5 (including)
JunosJuniper19.3-r2-s6 (including)19.3-r2-s6 (including)
JunosJuniper19.4 (including)19.4 (including)
JunosJuniper19.4-r1 (including)19.4-r1 (including)
JunosJuniper19.4-r1-s1 (including)19.4-r1-s1 (including)
JunosJuniper19.4-r1-s2 (including)19.4-r1-s2 (including)
JunosJuniper19.4-r1-s3 (including)19.4-r1-s3 (including)
JunosJuniper19.4-r1-s4 (including)19.4-r1-s4 (including)
JunosJuniper19.4-r2 (including)19.4-r2 (including)
JunosJuniper19.4-r2-s1 (including)19.4-r2-s1 (including)
JunosJuniper19.4-r2-s2 (including)19.4-r2-s2 (including)
JunosJuniper19.4-r2-s3 (including)19.4-r2-s3 (including)
JunosJuniper19.4-r2-s4 (including)19.4-r2-s4 (including)
JunosJuniper19.4-r2-s5 (including)19.4-r2-s5 (including)
JunosJuniper19.4-r2-s6 (including)19.4-r2-s6 (including)
JunosJuniper19.4-r2-s7 (including)19.4-r2-s7 (including)
JunosJuniper20.1 (including)20.1 (including)
JunosJuniper20.1-r1 (including)20.1-r1 (including)
JunosJuniper20.1-r1-s1 (including)20.1-r1-s1 (including)
JunosJuniper20.1-r1-s2 (including)20.1-r1-s2 (including)
JunosJuniper20.1-r1-s3 (including)20.1-r1-s3 (including)
JunosJuniper20.1-r1-s4 (including)20.1-r1-s4 (including)
JunosJuniper20.2 (including)20.2 (including)
JunosJuniper20.2-r1 (including)20.2-r1 (including)
JunosJuniper20.2-r1-s1 (including)20.2-r1-s1 (including)
JunosJuniper20.2-r1-s2 (including)20.2-r1-s2 (including)
JunosJuniper20.2-r1-s3 (including)20.2-r1-s3 (including)

Potential Mitigations

References