漏洞更新 - Juniper釋出Juniper Networks Junos OS安全漏洞更新(CVE-2023-22396)

         



Juniper釋出Juniper Networks Junos OS安全漏洞更新
(CVE-2023-22396)

一、摘要

        Juniper Networks Junos OS存在Uncontrolled Resource Consumption漏洞(CVE-2023-22396),允許未經授權之遠端攻擊者發送精心製作的TCP封包到目的端設備,最終導致阻斷服務之狀況


、存在風險

        Juniper Networks Junos OS存在Uncontrolled Resource Consumption漏洞,允許未經授權之遠端攻擊者發送精心製作的TCP封包到目的端設備,最終導致阻斷服務之狀況,影響版本如下:

  • 12.3 version 12.3R12-S19 and later versions
  • 15.1 version 15.1R7-S10 and later versions
  • 17.3 version 17.3R3-S12 and later versions
  • 18.4 version 18.4R3-S9 and later versions
  • 19.1 version 19.1R3-S7 and later versions
  • 19.2 version 19.2R3-S3 and later versions
  • 19.3 version 19.3R2-S7, 19.3R3-S3 and later versions prior to 19.3R3-S7
  • 19.4 version 19.4R2-S7, 19.4R3-S5 and later versions prior to 19.4R3-S10
  • 20.1 version 20.1R3-S1 and later versions
  • 20.2 version 20.2R3-S2 and later versions prior to 20.2R3-S6
  • 20.3 version 20.3R3-S1 and later versions prior to 20.3R3-S6
  • 20.4 version 20.4R2-S2, 20.4R3 and later versions prior to 20.4R3-S5
  • 21.1 version 21.1R2 and later versions prior to 21.1R3-S4
  • 21.2 version 21.2R1-S1, 21.2R2 and later versions prior to 21.2R3-S3
  • 21.3 versions prior to 21.3R3-S2
  • 21.4 versions prior to 21.4R3
  • 22.1 versions prior to 22.1R2-S1, 22.1R3
  • 22.2 versions prior to 22.2R1-S2, 22.2R2
  • 22.3 versions prior to 22.3R1-S1, 22.3R2

        建議改善措施:請維護廠商協助更新系統或提供解決方案。

    
   情資報告連結:https://supportportal.juniper.net/s/article/2023-01-Security-Bulletin-Junos-OS-Receipt-of-crafted-TCP-packets-on-Ethernet-console-port-results-in-MBUF-leak-leading-to-Denial-of-Service-DoS-CVE-2023-22396?language=en_US

這個網誌中的熱門文章

漏洞分享 - Fortinet 產品存在多個漏洞

-->

漏洞分享 - Fortinet 產品存在多個漏洞

-->

漏洞分享 - Fortinet 產品存在多個漏洞

-->

案例分享-某企業AD上百組帳號大量登入失敗導致鎖定事件

-->

資安威脅趨勢 - 醫院遭CrazyHunter勒索軟體持續攻擊

-->

漏洞更新 - VMware修補vCenter Server heap-overflow和privilege escalation漏洞

-->

漏洞分享 - Fortinet 產品存在多個漏洞

-->

漏洞分享 - Fortinet 產品多個漏洞

-->

漏洞分享 - Fortinet 產品存在多個漏洞

-->

漏洞分享 - Fortinet 產品存在多個漏洞

-->