SRX5000 Series with SPC3, SRX4000 Series, and vSRX: When PowerMode IPsec is configured, the PFE will crash upon receipt of a malformed ESP packet
Published Oct 18, 2022
7.5
HIGHCVSS 3.1
EPSS 0.67%
Description
An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). On SRX5000 Series with SPC3, SRX4000 Series, and vSRX, when PowerMode IPsec is configured and a malformed ESP packet matching an established IPsec tunnel is received the PFE crashes. This issue affects Juniper Networks Junos OS on SRX5000 Series with SPC3, SRX4000 Series, and vSRX: All versions prior to 19.4R2-S6, 19.4R3-S7; 20.1 versions prior to 20.1R3-S3; 20.2 versions prior to 20.2R3-S4; 20.3 versions prior to 20.3R3-S3; 20.4 versions prior to 20.4R3-S2; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R3; 21.3 versions prior to 21.3R1-S2, 21.3R2.
Affected products
-
- Version 20.1StatusaffectedConstraints<20.1R3-S3
- Version 20.2StatusaffectedConstraints<20.2R3-S4
- Version 20.3StatusaffectedConstraints<20.3R3-S3
- Version 20.4StatusaffectedConstraints<20.4R3-S2
- Version 21.1StatusaffectedConstraints<21.1R3
- Version 21.2StatusaffectedConstraints<21.2R3
- Version 21.3StatusaffectedConstraints<21.3R1-S2, 21.3R2
- Version unspecifiedStatusaffectedConstraints<19.4R2-S6, 19.4R3-S7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Juniper Networks | Junos OS | n/a |
|
- < 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 21.1
- 21.1
- 21.1
- 21.1
- 21.1
- 21.1
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.3
- 21.3
- 21.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The following software releases have been updated to resolve this specific issue: 19.4R2-S6, 19.4R3-S7, 20.1R3-S3, 20.2R3-S4, 20.3R3-S3, 20.4R3-S2, 21.1R3, 21.2R3, 21.3R1-S2, 21.3R2, 21.4R1, and all subsequent releases.
References (1)
- https://kb.juniper.net/JSA69900 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://kb.juniper.net/JSA69900 | Vendor Advisory |
Change history (0)
No recorded changes yet.