Database/Firmware, BMC & network fabric
Juniper Junos OS Packet Forwarding Engine (MX Series): Improper handling of unusual conditions in the Packet Forwarding
CVSS 7.5CVE-2023-44199Firmware, BMC & network fabriccurated
Impact
Improper handling of unusual conditions in the Packet Forwarding Engine lets an unauthenticated network attacker deny service. A PFE-level failure is worse than a control-plane one — it stops the data plane, so traffic stops even if the routing engine stays up.
Who can reach it
Unauthenticated, network-based, against the PFE on Junos MX platforms.
What to do
Junos upgrade plus reboot. MX platforms are usually the cluster's edge/border routers, so plan around a redundant pair — patch one side, fail over, patch the other.
References
Related entries
- AMI AptioV UEFI BIOS (EDK II network stack, IPv6): An infinite loop when the firmware parses unknown options in an IPv6CVE-2023-45232 · AMI AptioV UEFI BIOS (EDK II network stack, IPv6)High
- EDK II NetworkPkg (IPv6 Destination Options header, PadN option parsing): Same shape as the unknown-option hang butCVE-2023-45233 · EDK II NetworkPkg (IPv6 Destination Options header, PadN option parsing)High
- EDK II NetworkPkg (TCP initial sequence number generation): The firmware's TCP initial sequence numbersCVE-2023-45236 · EDK II NetworkPkg (TCP initial sequence number generation)High
- EDK II NetworkPkg (PseudoRandom number generation used by the network stack): The weak PRNG behind the previous issueCVE-2023-45237 · EDK II NetworkPkg (PseudoRandom number generation used by the network stack)High
- Lenovo XClarity Controller (XCC) - permission API: An authenticated XCC user can change the permissions of any userCVE-2023-4607 · Lenovo XClarity Controller (XCC) - permission APIHigh
- HPE iLO 5 / iLO 6 (authentication bypass): Authentication bypass on the iLO itself, remotely, with no credentialsCVE-2023-50272 · HPE iLO 5 / iLO 6 (authentication bypass)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.