CVE-2023-44190
Last modified
CVE-2023-44190 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10001, PTX10004, PTX10008, and PTX10016 devices allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream network. Due to this issue, the router will start forwarding traffic if a valid route is present in forwarding-table, causing a loop and congestion in the downstream layer-2 domain connected to the device. This issue affects Juniper Networks Junos OS Evolved on PTX10001, PTX10004, PTX10008, and PTX10016: * All versions prior to 21.4R3-S5-EVO; * 22.1 versions prior to 22.1R3-S4-EVO; * 22.2 versions 22.2R1-EVO and later; * 22.3 versions prior to 22.3R2-S2-EVO, 22.3R3-S1-EVO; * 22.4 versions prior to 22.4R2-S1-EVO, 22.4R3-EVO; * 23.2 versions prior to 23.2R1-S1-EVO, 23.2R2-EVO. . EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10001, PTX10004, PTX10008, and PTX10016 devices allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream network. Due to this issue, the router will start forwarding traffic if a valid route is present in forwarding-table, causing a loop and congestion in the downstream layer-2 domain connected to the device. This issue affects Juniper Networks Junos OS Evolved on PTX10001, PTX10004, PTX10008, and PTX10016: * All versions prior to 21.4R3-S5-EVO; * 22.1 versions prior to 22.1R3-S4-EVO; * 22.2 versions 22.2R1-EVO and later; * 22.3 versions prior to 22.3R2-S2-EVO, 22.3R3-S1-EVO; * 22.4 versions prior to 22.4R2-S1-EVO, 22.4R3-EVO; * 23.2 versions prior to 23.2R1-S1-EVO, 23.2R2-EVO.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos Os Evolved | < 21.4 | — |
| Juniper | Junos Os Evolved | 21.4 | — |
| Juniper | Junos Os Evolved | 22.1 | R1 |
| Juniper | Junos Os Evolved | 22.2 | R1 |
| Juniper | Junos Os Evolved | 22.3 | R1 |
| Juniper | Junos Os Evolved | 22.4 | R1 |
| Juniper | Junos Os Evolved | 23.2 | R1 |
References
- https://supportportal.juniper.net/JSA73154Vendor Advisory
- https://supportportal.juniper.net/JSA73154Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-44190?
How severe is CVE-2023-44190?
How do I fix CVE-2023-44190?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-44185 An Improper Input Validation vulnerability in the routing p…7.5
- CVE-2023-44186 An Improper Handling of Exceptional Conditions vulnerabilit…7.5
- CVE-2023-44187An Exposure of Sensitive Information vulnerability in the 'f…5.5
- CVE-2023-44188 A Time-of-check Time-of-use (TOCTOU) Race Condition vulnera…5.3
- CVE-2023-44189 An Origin Validation vulnerability in MAC address validatio…5.4
- CVE-2023-4419The LMS5xx uses hard-coded credentials, which potentially al…8.8
- CVE-2023-44191 An Allocation of Resources Without Limits or Throttling vul…7.5
- CVE-2023-44192 An Improper Input Validation vulnerability in the Packet Fo…7.5
- CVE-2023-44193 An Improper Release of Memory Before Removing Last Referenc…5.5
- CVE-2023-44194 An Incorrect Default Permissions vulnerability in Juniper N…7.8
- CVE-2023-44195 An Improper Restriction of Communication Channel to Intende…5.3
- CVE-2023-44196 An Improper Check for Unusual or Exceptional Conditions in …6.5
Are you affected by CVE-2023-44190?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
