A Use of Incorrect Byte Ordering
vulnerability
in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS on SRX300 Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
When a BGP update is received over an established BGP session which contains a specific, valid, optional, transitive path attribute, rpd will crash and restart.
This issue affects eBGP and iBGP over IPv4 and IPv6.
This issue affects:
Junos OS:
The product receives input from an upstream component, but it does not account for byte ordering (e.g. big-endian and little-endian) when processing the input, causing an incorrect number or value to be used.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Junos | Juniper | 22.1-r1 (including) | 22.1-r1 (including) |
| Junos | Juniper | 22.1-r1-s1 (including) | 22.1-r1-s1 (including) |
| Junos | Juniper | 22.1-r1-s2 (including) | 22.1-r1-s2 (including) |
| Junos | Juniper | 22.1-r2 (including) | 22.1-r2 (including) |
| Junos | Juniper | 22.1-r2-s1 (including) | 22.1-r2-s1 (including) |
| Junos | Juniper | 22.1-r2-s2 (including) | 22.1-r2-s2 (including) |
| Junos | Juniper | 22.1-r3 (including) | 22.1-r3 (including) |
| Junos | Juniper | 22.1-r3-s1 (including) | 22.1-r3-s1 (including) |
| Junos | Juniper | 22.1-r3-s2 (including) | 22.1-r3-s2 (including) |
| Junos | Juniper | 22.1-r3-s3 (including) | 22.1-r3-s3 (including) |
| Junos | Juniper | 22.3 (including) | 22.3 (including) |
| Junos | Juniper | 22.3-r1 (including) | 22.3-r1 (including) |
| Junos | Juniper | 22.3-r1-s1 (including) | 22.3-r1-s1 (including) |
| Junos | Juniper | 22.3-r1-s2 (including) | 22.3-r1-s2 (including) |
| Junos | Juniper | 22.3-r2 (including) | 22.3-r2 (including) |
| Junos | Juniper | 22.3-r2-s1 (including) | 22.3-r2-s1 (including) |
| Junos | Juniper | 22.3-r2-s2 (including) | 22.3-r2-s2 (including) |
| Junos | Juniper | 22.3-r3 (including) | 22.3-r3 (including) |
| Junos | Juniper | 22.3-r3-s1 (including) | 22.3-r3-s1 (including) |
| Junos | Juniper | 22.3-r3-s2 (including) | 22.3-r3-s2 (including) |
| Junos | Juniper | 22.4 (including) | 22.4 (including) |
| Junos | Juniper | 22.4-r1 (including) | 22.4-r1 (including) |
| Junos | Juniper | 22.4-r1-s1 (including) | 22.4-r1-s1 (including) |
| Junos | Juniper | 22.4-r1-s2 (including) | 22.4-r1-s2 (including) |
| Junos | Juniper | 22.4-r2 (including) | 22.4-r2 (including) |
| Junos | Juniper | 22.4-r2-s1 (including) | 22.4-r2-s1 (including) |
| Junos | Juniper | 22.4-r2-s2 (including) | 22.4-r2-s2 (including) |
| Junos | Juniper | 22.4-r3 (including) | 22.4-r3 (including) |
| Junos | Juniper | 22.4-r3-s1 (including) | 22.4-r3-s1 (including) |
| Junos | Juniper | 23.2 (including) | 23.2 (including) |
| Junos | Juniper | 23.2-r1 (including) | 23.2-r1 (including) |
| Junos | Juniper | 23.2-r1-s1 (including) | 23.2-r1-s1 (including) |
| Junos | Juniper | 23.2-r1-s2 (including) | 23.2-r1-s2 (including) |
| Junos | Juniper | 23.4 (including) | 23.4 (including) |
| Junos | Juniper | 23.4-r1 (including) | 23.4-r1 (including) |
| Junos | Juniper | 23.4-r1-s1 (including) | 23.4-r1-s1 (including) |
| Junos | Juniper | 23.4-r1-s2 (including) | 23.4-r1-s2 (including) |