Juniper Networks Junos OS
cpe:2.3:a:juniper:junos:*:*:*:*:*:*:*, +2 more
- < 22.4R3-S1
- >= 23.2, < 23.2R2
- >= 23.4, < 23.4R2
A memory leak vulnerability has been identified in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series. This vulnerability allows an adjacent, unauthenticated attacker to cause a memory leak that eventually leads to a complete denial-of-service (DoS). In scenarios involving DHCPv6 over PPPoE or VLAN with Active lease query or Bulk lease query, each subscriber logout results in a small memory leak. Once the available memory is exhausted, jdhcpd crashes and restarts, causing a total service disruption until the process recovers. The vulnerability affects all Junos OS versions prior to 22.4R3-S1, as well as 23.2 versions before 23.2R2 and 23.4 versions before 23.4R2.
Exploitation of this vulnerability causes jdhcpd to consume excessive memory, leading to a crash and restart of the process. This disruption causes a complete service impact until the process has recovered.
Users can upgrade to Junos OS versions 22.4R3-S1, 23.2R2, 23.4R2, 24.2R1, or any subsequent release to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.