漏洞标题
Junos OS: 在 NSR 启用的设备上,BGP Flap 导致内存泄漏。
漏洞描述信息
在Juniper Networks的Nonstop active routing(NSR)组件中, incomplete cleanup 漏洞可能导致相邻未验证的攻击者引起内存泄漏,从而导致拒绝服务(DoS)。
在所有Juniper OS平台上,当NSR被启用时,BGP门控环流将引起内存泄漏。系统手动重启将恢复服务。
可以使用以下命令来监控内存使用情况。
用户名@主机> 显示机架路由引擎,无转发
用户名@主机> 显示系统内存 | 无更多
此问题影响:
Juniper Networks和Juniper OS
* 21.2版本早于21.2R3-S5;
* 21.3版本早于21.3R3-S4;
* 21.4版本早于21.4R3-S4;
* 22.1版本早于22.1R3-S2;
* 22.2版本早于22.2R3-S2;
* 22.3版本早于22.3R2-S1,22.3R3;
* 22.4版本早于22.4R1-S2,22.4R2。
此问题不会影响到20.4R3-S7之前的Juniper OS版本。
CVSS信息
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
漏洞类别
在移除最后引用时对内存的释放不恰当(内存泄露)
漏洞标题
Junos OS: BGP flap on NSR-enabled devices causes memory leak
漏洞描述信息
An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause memory leak leading to Denial of Service (DoS).
On all Junos OS platforms, when NSR is enabled, a BGP flap will cause memory leak. A manual reboot of the system will restore the services.
Note: NSR is not supported on the SRX Series and is therefore not affected by this vulnerability.
The memory usage can be monitored using the below commands.
user@host> show chassis routing-engine no-forwarding
user@host> show system memory | no-more
This issue affects:
Juniper Networks Junos OS
* 21.2 versions earlier than 21.2R3-S5;
* 21.3 versions earlier than 21.3R3-S4;
* 21.4 versions earlier than 21.4R3-S4;
* 22.1 versions earlier than 22.1R3-S2;
* 22.2 versions earlier than 22.2R3-S2;
* 22.3 versions earlier than 22.3R2-S1, 22.3R3;
* 22.4 versions earlier than 22.4R1-S2, 22.4R2.
This issue does not affect Junos OS versions earlier than 20.4R3-S7.
CVSS信息
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
漏洞类别
清理环节不完整
漏洞标题
Juniper Networks Junos OS 和 Junos OS Evolved 安全漏洞
漏洞描述信息
Juniper Networks Junos OS和Juniper Networks Junos OS Evolved都是美国瞻博网络(Juniper Networks)公司的产品。Juniper Networks Junos OS是一套专用于该公司的硬件设备的网络操作系统。该操作系统提供了安全编程接口和Junos SDK。Juniper Networks Junos OS Evolved是Junos OS 的升级版系统。 Juniper Networks Junos OS 和 Junos OS Evol
CVSS信息
N/A
漏洞类别
其他