Juniper Networks Junos OS
cpe:2.3:a:juniper:junos:*:*:*:*:*:*:*, +3 more
- < 21.4R3-S9
- >= 22.2, < 22.2R3-S5
- >= 22.4, < 22.4R3-S5
- >= 23.2, < 23.2R2-S3
- >= 23.4, < 23.4R2-S3
- >= 24.2, < 24.2R2
A heap-based buffer overflow vulnerability has been identified in the flexible PIC concentrator (FPC) of Juniper Networks Junos OS. This vulnerability affects EX2300, EX3400, EX4100, EX4300, EX4300MP, EX4400, EX4600, EX4650-48Y, and QFX5k Series switches. The issue allows an attacker to send a specific DHCP packet to the device, causing the FPC to crash and restart, which leads to a denial-of-service (DoS) condition. If DHCP Option 82 is enabled, the vulnerability could also result in memory corruption, disrupting packet forwarding. Furthermore, due to the nature of the heap-based overflow, there is a possibility of remote code execution within the FPC, granting complete control over the vulnerable component.
Exploitation of this vulnerability causes the FPC to crash, disrupts packet forwarding, and creates a sustained denial-of-service condition. Additionally, the heap-based buffer overflow could be exploited for remote code execution within the FPC, allowing complete control over the vulnerable component.
Users can upgrade to Junos OS versions 21.4R3-S9, 22.2R3-S5, 22.4R3-S5, 23.2R2-S3, 23.4R2-S3, or 24.2R2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.