CVE-2023-22405 is an Improper Preservation of Consistency vulnerability in Juniper Networks Junos OS affecting QFX5k and EX46xx series devices. When configured with "service-provider/SP style" switching and mac-limiting on an Aggregated Ethernet interface, a PFE restart or device reboot can cause mac-limiting to fail, leading to a Denial of Service due to resource exhaustion. The vulnerability has a CVSS score of 6.5 (Medium), indicating an adjacent attack vector with low complexity and high impact on availability. No authentication or user interaction is required for exploitation. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
20.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.2:-:*:*:*:*:*:* | ||
20.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.2:r1:*:*:*:*:*:* | ||
20.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.2:r1-s1:*:*:*:*:*:* | ||
20.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.2:r1-s2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.