Executive Summary

Informations
Name CVE-2023-28974 First vendor Publication 2023-04-17
Vendor Cve Last vendor Modification 2023-04-28

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 6.5
Base Score 6.5 Environmental Score 6.5
impact SubScore 3.6 Temporal Score 6.5
Exploitabality Sub Score 2.8
 
Attack Vector Adjacent Attack Complexity Low
Privileges Required None User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). In a Broadband Edge / Subscriber Management scenario on MX Series when a specifically malformed ICMP packet addressed to the device is received from a subscriber the bbe-smgd will crash, affecting the subscriber sessions that are connecting, updating, or terminating. Continued receipt of such packets will lead to a sustained DoS condition. When this issue happens the below log can be seen if the traceoptions for the processes smg-service are enabled: BBE_TRACE(TRACE_LEVEL_INFO, "%s: Dropped unsupported ICMP PKT ... This issue affects Juniper Networks Junos OS on MX Series: All versions prior to 19.4R3-S11; 20.2 versions prior to 20.2R3-S7; 20.3 versions prior to 20.3R3-S6; 20.4 versions prior to 20.4R3-S6; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S4; 21.3 versions prior to 21.3R3-S3; 21.4 versions prior to 21.4R3-S2; 22.1 versions prior to 22.1R2-S2, 22.1R3; 22.2 versions prior to 22.2R2; 22.3 versions prior to 22.3R1-S2, 22.3R2.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28974

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-754 Improper Check for Unusual or Exceptional Conditions

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1
Hardware 1
Os 985

Sources (Detail)

Source Url
CONFIRM https://supportportal.juniper.net/JSA70599

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
Date Informations
2024-02-02 02:44:53
  • Multiple Updates
2024-02-01 12:29:55
  • Multiple Updates
2023-10-21 02:29:44
  • Multiple Updates
2023-09-05 13:40:17
  • Multiple Updates
2023-09-05 01:29:07
  • Multiple Updates
2023-09-02 13:38:29
  • Multiple Updates
2023-09-02 01:29:34
  • Multiple Updates
2023-08-12 13:43:52
  • Multiple Updates
2023-08-12 01:28:49
  • Multiple Updates
2023-08-11 13:35:18
  • Multiple Updates
2023-08-11 01:29:42
  • Multiple Updates
2023-08-06 13:32:29
  • Multiple Updates
2023-08-06 01:28:27
  • Multiple Updates
2023-08-04 13:32:57
  • Multiple Updates
2023-08-04 01:28:52
  • Multiple Updates
2023-07-28 02:21:06
  • Multiple Updates
2023-07-14 13:32:45
  • Multiple Updates
2023-07-14 01:28:28
  • Multiple Updates
2023-04-28 21:27:23
  • Multiple Updates
2023-04-18 09:27:15
  • Multiple Updates
2023-04-18 05:27:18
  • First insertion