Juniper Networks Junos OS
cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*
- < 21.2R3-S9
- >= 21.4, < 21.4R3-S10
- >= 22.2, < 22.2R3-S6
- >= 22.4, < 22.4R3-S4
- >= 23.2, < 23.2R2-S2
- >= 23.4, < 23.4R2
A buffer access vulnerability with an incorrect length value has been identified in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved. This vulnerability allows an unauthenticated, network-based attacker to cause a denial-of-service condition. The issue arises when a specific ICMPv6 packet is sent to an interface configured to send router advertisements. This causes the RPD process to crash and restart. Continued receipt of the packet leads to a sustained denial-of-service condition. The vulnerability only affects systems with IPv6 enabled.
Exploitation of this vulnerability causes the RPD process to crash and restart, leading to a denial-of-service condition that can be sustained with continued receipt of the malicious ICMPv6 packets.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.