CVE-2023-4481 is an Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved. It allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS) by sending specific crafted BGP UPDATE messages over an established BGP session. This can tear down BGP sessions or propagate to affect remote systems, leading to a sustained DoS condition. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a significant risk. It requires no user interaction (UI:N) and has low attack complexity (AC:L), making it relatively easy to exploit remotely (AV:N). The primary impact is a Denial of Service (A:H), with no impact on confidentiality or integrity. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available. However, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.4:-:*:*:*:*:*:* | ||
20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.4:r1:*:*:*:*:*:* | ||
20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.4:r1-s1:*:*:*:*:*:* | ||
20.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:20.4:r2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.