CVE-2023-28976 is an Improper Check for Unusual or Exceptional Conditions vulnerability affecting Juniper Networks Junos OS on MX Series devices. An unauthenticated, network-based attacker can trigger a Denial of Service (DoS) by sending specific traffic at a rate exceeding the device's DDoS protection limit, causing the packet forwarding engine (PFE) to crash and restart. Continued receipt of this traffic results in a sustained DoS. This vulnerability has a CVSS v3.1 score of 7.5 (HIGH), indicating a high severity. The attack requires no user interaction or privileges, and its impact is limited to availability. The complexity of the attack is low, as it relies on exceeding a rate limit. Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 19.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
19.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:19.1:-:*:*:*:*:*:* | ||
19.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:19.1:r1:*:*:*:*:*:* | ||
19.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:19.1:r1-s1:*:*:*:*:*:* | ||
19.1CPE matchmatch criteria | cpe:2.3:o:juniper:junos:19.1:r1-s2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.