Juniper Junos OS
cpe:2.3:a:juniper:junos:*:*:*:*:*:*:*, +3 more
- < 21.2R3-S9
- >= 21.4, < 21.4R3-S10
- >= 22.2, < 22.2R3-S6
- >= 22.4, < 22.4R3-S6
- >= 23.2, < 23.2R2-S3
- >= 23.4, < 23.4R2-S4
- >= 24.2, < 24.2R2
A denial-of-service vulnerability has been identified in the Juniper DHCP Daemon (jdhcpd) of Junos OS and Junos OS Evolved. This vulnerability allows an unauthenticated, adjacent attacker to cause the jdhcpd process to crash by sending a specifically malformed DHCP packet from a DHCP client. The crash leads to a temporary unavailability of the DHCP service, causing a sustained denial-of-service condition. Although the DHCP process automatically restarts to recover the service, this issue can be disruptive. The vulnerability occurs when dhcp-security is enabled.
Exploitation of this vulnerability causes the jdhcpd process to crash, leading to a temporary disruption of the DHCP service. While the service automatically restarts, the interruption can cause sustained availability issues.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.