Juniper Security Update 31 August 2023

Juniper has released a security update to fix a vulnerability across Junos OS and Junos OS Evolved.

The addressed vulnerability could allow the remote attacker to cause a denial of service attack on the affected products by sending a specially crafted BGP UPDATE message.

Juniper Networks Junos OS and Junos OS Evolved Denial of Service Vulnerability (CVE-2023-4481):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service

The affected products:

  • All versions of Junos OS prior to 23.4R1.
  • All versions of Junos OS Evolved prior to 23.4R1-EVO.
Vulnerabilities

CVE-2023-4481

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Juniper Security Advisory

References