CVE-2023-22402

MEDIUM

Juniper Networks Junos OS Evolved - DoS

Title source: llm
STIX 2.1

Description

A Use After Free vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). In a Non Stop Routing (NSR) scenario, an unexpected kernel restart might be observed if "bgp auto-discovery" is enabled and if there is a BGP neighbor flap of auto-discovery sessions for any reason. This is a race condition which is outside of an attackers direct control and it depends on system internal timing whether this issue occurs. This issue affects Juniper Networks Junos OS Evolved: 21.3 versions prior to 21.3R3-EVO; 21.4 versions prior to 21.4R2-EVO; 22.1 versions prior to 22.1R2-EVO; 22.2 versions prior to 22.2R1-S1-EVO, 22.2R2-EVO.

References (1)

Core 1
Core References

Scores

CVSS v3 5.9
EPSS 0.0046
EPSS Percentile 64.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (4)
juniper/junos_os_evolved 21.3 (6 CPE variants)
juniper/junos_os_evolved 21.4 (4 CPE variants)
juniper/junos_os_evolved 22.1 r1 (3 CPE variants)
juniper/junos_os_evolved 22.2 r1
Published Jan 13, 2023
Tracked Since Feb 18, 2026