CVE-2023-22398
An Access of Uninitialized Pointer vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). When an MPLS ping is performed on BGP LSPs, the RPD might crash. Repeated execution of this operation will lead to a sustained DoS. This issue affects: Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S12.
19.1 versions prior to 19.1R3-S9.
19.2 versions prior to 19.2R1-S9, 19.2R3-S5.
19.3 versions prior to 19.3R3-S6.
19.4 versions prior to 19.4R2-S7, 19.4R3-S8.
20.1 versions prior to 20.1R3-S4.
20.2 versions prior to 20.2R3-S5.
20.3 versions prior to 20.3R3-S5.
20.4 versions prior to 20.4R3-S4.
21.1 versions prior to 21.1R1-S1, 21.1R2.
Juniper Networks Junos OS Evolved: All versions prior to 20.4R3-S4.
21.1 versions prior to 21.1R2-EVO.
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence