Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22408


An Improper Validation of Array Index vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX 5000 Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). When an attacker sends an SIP packets with a malformed SDP field then the SIP ALG can not process it which will lead to an FPC crash and restart. Continued receipt of these specific packets will lead to a sustained Denial of Service. This issue can only occur when both below mentioned conditions are fulfilled: 1. Call distribution needs to be enabled: [security alg sip enable-call-distribution] 2. The SIP ALG needs to be enabled, either implicitly / by default or by way of configuration. To confirm whether SIP ALG is enabled on SRX, and MX with SPC3 use the following command: user@host> show security alg status | match sip SIP : Enabled This issue affects Juniper Networks Junos OS on SRX 5000 Series: 20.4 versions prior to 20.4R3-S5; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S3; 21.3 versions prior to 21.3R3-S3; 21.4 versions prior to 21.4R3-S2; 22.1 versions prior to 22.1R2-S2, 22.1R3; 22.2 versions prior to 22.2R3; 22.3 versions prior to 22.3R1-S1, 22.3R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.


Published

2023-01-13T00:15:11.157

Last Modified

2024-11-21T07:44:45.497

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-129
  • Type: Primary
    CWE-129

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System juniper junos 20.4 Yes
Operating System juniper junos 20.4 Yes
Operating System juniper junos 20.4 Yes
Operating System juniper junos 20.4 Yes
Operating System juniper junos 20.4 Yes
Operating System juniper junos 20.4 Yes
Operating System juniper junos 20.4 Yes
Operating System juniper junos 20.4 Yes
Operating System juniper junos 20.4 Yes
Operating System juniper junos 20.4 Yes
Operating System juniper junos 20.4 Yes
Operating System juniper junos 21.1 Yes
Operating System juniper junos 21.1 Yes
Operating System juniper junos 21.1 Yes
Operating System juniper junos 21.1 Yes
Operating System juniper junos 21.1 Yes
Operating System juniper junos 21.1 Yes
Operating System juniper junos 21.1 Yes
Operating System juniper junos 21.1 Yes
Operating System juniper junos 21.1 Yes
Operating System juniper junos 21.1 Yes
Operating System juniper junos 21.2 Yes
Operating System juniper junos 21.2 Yes
Operating System juniper junos 21.2 Yes
Operating System juniper junos 21.2 Yes
Operating System juniper junos 21.2 Yes
Operating System juniper junos 21.2 Yes
Operating System juniper junos 21.2 Yes
Operating System juniper junos 21.2 Yes
Operating System juniper junos 21.2 Yes
Operating System juniper junos 21.2 Yes
Operating System juniper junos 21.3 Yes
Operating System juniper junos 21.3 Yes
Operating System juniper junos 21.3 Yes
Operating System juniper junos 21.3 Yes
Operating System juniper junos 21.3 Yes
Operating System juniper junos 21.3 Yes
Operating System juniper junos 21.3 Yes
Operating System juniper junos 21.3 Yes
Operating System juniper junos 21.3 Yes
Operating System juniper junos 21.3 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 22.1 Yes
Operating System juniper junos 22.1 Yes
Operating System juniper junos 22.1 Yes
Operating System juniper junos 22.1 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.3 Yes
Hardware juniper srx5400 - No
Hardware juniper srx5600 - No
Hardware juniper srx5800 - No

References