CVE-2023-28959: Junos OS: QFX10002: PFE wedges and restarts upon receipt of specific malformed packets
An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on QFX10002 allows an unauthenticated, adjacent attacker on the local broadcast domain sending a malformed packet to the device, causing all PFEs other than the inbound PFE to wedge and to eventually restart, resulting in a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue can only be triggered by sending a specific malformed packet to the device. Transit traffic does not trigger this issue. An indication of this issue occurring can be seen through the following log messages: fpc0 exprhostboundpackethandler: Receive pe 73? fpc0 Cmerror Op Set: PE Chip: PE0[0]: PGQ:miscintr: 0x00000020: Enqueue of a packet with out-of-range VOQ in 192K-VOQ mode (URI: /fpc/0/pfe/0/cm/0/PEChip/0/PECHIPCMERRORPGQMISCINTEVENTSENQ192KVIOL) The logs list below can also be observed when this issue occurs fpc0 Error: /fpc/0/pfe/0/cm/0/PEChip/0/PECHIPCMERRORPGQMISCINTEVENTSENQ192KVIOL (0x210107), scope: pfe, category: functional, severity: major, module: PE Chip, type: Description for PECHIPCMERRORPGQMISCINTEVENTSENQ192KVIOL fpc0 Performing action cmalarm for error /fpc/0/pfe/0/cm/0/PEChip/0/PECHIPCMERRORPGQMISCINTEVENTSENQ192KVIOL (0x210107) in module: PE Chip with scope: pfe category: functional level: major fpc0 Error: /fpc/0/pfe/0/cm/0/PEChip/0/PECHIPCMERRORCMINTREGDCHKPIPE (0x21011a), scope: pfe, category: functional, severity: fatal, module: PE Chip, type: Description for PECHIPCMERRORCMINTREGDCHKPIPE fpc0 Performing action cmalarm for error /fpc/0/pfe/0/cm/0/PEChip/0/PECHIPCMERRORCMINTREGDCHKPIPE (0x21011a) in module: PE Chip with scope: pfe category: functional level: fatal fpc0 Performing action disable-pfe for error /fpc/0/pfe/0/cm/0/PEChip/0/PECHIPCMERRORCMINTREGDCHKPIPE (0x21011a) in module: PE Chip with scope: pfe category: functional level: fatal This issue affects Juniper Networks Junos OS on QFX10002: All versions prior to 19.1R3-S10; 19.4 versions prior to 19.4R3-S11; 20.2 versions prior to 20.2R3-S7; 20.4 versions prior to 20.4R3-S6; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S4; 21.3 versions prior to 21.3R3-S3; 21.4 versions prior to 21.4R3-S2; 22.1 versions prior to 22.1R3-S1; 22.2 versions prior to 22.2R2-S1, 22.2R3; 22.3 versions prior to 22.3R1-S2, 22.3R2.
Other sources
Juniper Networks Junos OS is vulnerable to a denial of service, caused by an improper check or handling of exceptional conditions vulnerability in packet processing. By sending a malformed packet, an attacker could exploit this vulnerability to cause a denial of service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28959?
The severity of CVE-2023-28959 is classified as critical due to the potential for remote code execution by an unauthenticated adjacent attacker.
How do I fix CVE-2023-28959?
To fix CVE-2023-28959, upgrade your Junos OS to a version above 19.4 or implement the recommended patches from Juniper Networks.
Which devices are affected by CVE-2023-28959?
CVE-2023-28959 affects Juniper QFX10002 devices running vulnerable versions of Junos OS.
Can an attacker exploit CVE-2023-28959 remotely?
No, an attacker must be on the local broadcast domain to exploit CVE-2023-28959.
What should I do if I suspect exploitation of CVE-2023-28959?
If you suspect exploitation of CVE-2023-28959, review your logs for unusual activity and immediately apply the security patches or upgrade the affected devices.