CVE-2023-22402

CVSS V2 None CVSS V3 None
Description
A Use After Free vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). In a Non Stop Routing (NSR) scenario, an unexpected kernel restart might be observed if "bgp auto-discovery" is enabled and if there is a BGP neighbor flap of auto-discovery sessions for any reason. This is a race condition which is outside of an attackers direct control and it depends on system internal timing whether this issue occurs. This issue affects Juniper Networks Junos OS Evolved: 21.3 versions prior to 21.3R3-EVO; 21.4 versions prior to 21.4R2-EVO; 22.1 versions prior to 22.1R2-EVO; 22.2 versions prior to 22.2R1-S1-EVO, 22.2R2-EVO.
Overview
  • CVE ID
  • CVE-2023-22402
  • Assigner
  • sirt@juniper.net
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-01-13T00:15:10
  • Last Modified Date
  • 2023-01-20T14:53:01
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:o:juniper:junos_os_evolved:21.3:-:*:*:*:*:*:* 1 OR
cpe:2.3:o:juniper:junos_os_evolved:21.3:r1:*:*:*:*:*:* 1 OR
cpe:2.3:o:juniper:junos_os_evolved:21.3:r1-s1:*:*:*:*:*:* 1 OR
cpe:2.3:o:juniper:junos_os_evolved:21.3:r2:*:*:*:*:*:* 1 OR
cpe:2.3:o:juniper:junos_os_evolved:21.3:r2-s1:*:*:*:*:*:* 1 OR
cpe:2.3:o:juniper:junos_os_evolved:21.3:r2-s2:*:*:*:*:*:* 1 OR
cpe:2.3:o:juniper:junos_os_evolved:21.4:-:*:*:*:*:*:* 1 OR
cpe:2.3:o:juniper:junos_os_evolved:21.4:r1:*:*:*:*:*:* 1 OR
cpe:2.3:o:juniper:junos_os_evolved:21.4:r1-s1:*:*:*:*:*:* 1 OR
cpe:2.3:o:juniper:junos_os_evolved:21.4:r1-s2:*:*:*:*:*:* 1 OR
cpe:2.3:o:juniper:junos_os_evolved:22.1:r1:*:*:*:*:*:* 1 OR
cpe:2.3:o:juniper:junos_os_evolved:22.1:r1-s1:*:*:*:*:*:* 1 OR
cpe:2.3:o:juniper:junos_os_evolved:22.1:r1-s2:*:*:*:*:*:* 1 OR
cpe:2.3:o:juniper:junos_os_evolved:22.2:r1:*:*:*:*:*:* 1 OR
References
Reference URL Reference Tags
https://kb.juniper.net/JSA70198
History
Created Old Value New Value Data Type Notes
2023-01-13 00:20:46 Added to TrackCVE
2023-01-13 00:20:47 Weakness Enumeration new
2023-01-13 05:15:11 2023-01-13T05:12:35 CVE Modified Date updated
2023-01-13 05:15:12 Received Awaiting Analysis Vulnerability Status updated
2023-01-19 16:15:18 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-20 15:14:46 2023-01-20T14:53:01 CVE Modified Date updated
2023-01-20 15:14:46 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-20 15:14:49 CPE Information updated