CVE-2023-22414
Last modified
CVE-2023-22414 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A Missing Release of Memory after Effective Lifetime vulnerability in Flexible PIC Concentrator (FPC) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker from the same shared physical or logical network, to cause a heap memory leak and leading to FPC crash. On all Junos PTX Series and QFX10000 Series, when specific EVPN VXLAN Multicast packets are processed, an FPC heap memory leak is observed. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
A Missing Release of Memory after Effective Lifetime vulnerability in Flexible PIC Concentrator (FPC) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker from the same shared physical or logical network, to cause a heap memory leak and leading to FPC crash. On all Junos PTX Series and QFX10000 Series, when specific EVPN VXLAN Multicast packets are processed, an FPC heap memory leak is observed. The FPC memory usage can be monitored using the CLI command "show heap extensive". Following is an example output. ID Base Total(b) Free(b) Used(b) % Name Peak used % -- -------- --------- --------- --------- --- ----------- ----------- 0 37dcf000 3221225472 1694526368 1526699104 47 Kernel 47 1 17dcf000 1048576 1048576 0 0 TOE DMA 0 2 17ecf000 1048576 1048576 0 0 DMA 0 3 17fcf000 534773760 280968336 253805424 47 Packet DMA 47 This issue affects: Juniper Networks Junos OS PTX Series and QFX10000 Series 20.2 versions prior to 20.2R3-S6; 20.3 versions prior to 20.3R3-S6; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S3; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R3; 22.1 versions prior to 22.1R2; 22.2 versions prior to 22.2R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.1R1 on PTX Series and QFX10000 Series.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | 20.2 | — |
| Juniper | Junos | 20.3 | — |
| Juniper | Junos | 20.4 | — |
| Juniper | Junos | 21.1 | — |
| Juniper | Junos | 21.2 | — |
| Juniper | Junos | 21.3 | — |
| Juniper | Junos | 21.4 | — |
| Juniper | Junos | 22.1 | R1 |
| Juniper | Junos | 22.2 | R1 |
References
- https://kb.juniper.net/JSA70210Vendor Advisory
- https://kb.juniper.net/JSA70210Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-22414?
How severe is CVE-2023-22414?
How do I fix CVE-2023-22414?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-22409An Unchecked Input for Loop Condition vulnerability in a NAT…5.5
- CVE-2023-2241A vulnerability, which was classified as critical, was found…5.3
- CVE-2023-22410A Missing Release of Memory after Effective Lifetime vulnera…6.5
- CVE-2023-22411An Out-of-Bounds Write vulnerability in Flow Processing Daem…7.5
- CVE-2023-22412An Improper Locking vulnerability in the SIP ALG of Juniper …7.5
- CVE-2023-22413An Improper Check or Handling of Exceptional Conditions vuln…7.5
- CVE-2023-22415An Out-of-Bounds Write vulnerability in the H.323 ALG of Jun…7.5
- CVE-2023-22416A Buffer Overflow vulnerability in SIP ALG of Juniper Networ…7.5
- CVE-2023-22417A Missing Release of Memory after Effective Lifetime vulnera…7.5
- CVE-2023-22418On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, …6.1
- CVE-2023-22419Out-of-bounds read vulnerability exists in Kostac PLC Progra…7.8
- CVE-2023-2242A vulnerability has been found in SourceCodester Online Comp…8.8
Are you affected by CVE-2023-22414?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
