Уязвимость одновременного выполнения с использованием общего ресурса с неправильной синхронизацией («состояние гонки») в механизме пересылки пакетов (PFE) ОС Juniper Networks Junos на устройствах серии SRX позволяет неаутентифицированному сетевому злоумышленнику вызвать отказ в обслуживании (DoS). В рамках обработки трафика с отслеживанием состояния на устройствах серии SRX потоки устанавливаются и удаляются, когда они больше не нужны. Во время процесса удаления тайм-аут потока должен быть установлен на 3 секунды, и, следовательно, поток должен быть удален вскоре после этого.
Из-за состояния гонки, возникающей при установке тайм-аута, существует вероятность (точные условия находятся вне контроля злоумышленников), что вместо этого для тайм-аута будет установлено очень высокое значение, превышающее 10 000 секунд: user@host> показать сеанс потока безопасности | тайм-аут матча Идентификатор сеанса: 98784248524, имя политики: PROD-FLOW/4, состояние высокой доступности: активное, время ожидания: 85250, состояние сеанса: действительное Это приведет к накоплению потоков, что можно наблюдать по постоянно растущему значению недействительных сеансов в выводе «показать сводку сеанса потока безопасности»: user@host> показать сводку сеанса потока безопасности | совпадение недействительно Недействительные сеансы: 216931Эти сеансы нельзя очистить вручную с помощью команды «очистить сеанс потока безопасности», что приведет либо к остановке пересылки (и систему необходимо будет восстановить вручную с перезагрузкой), либо к потоковому ядру и автоматической перезагрузке. Эта проблема затрагивает ОС Junos в серии SRX: * версии 24.2 до 24.2R2-S3, * версии 24.4 до 24.4R2-S1, 24.4R2-S2, * Версии 25.2 до 25.2R1-S2, 25.2R2. Эта проблема не затрагивает выпуски ранее 24.2R1;
Показать оригинальное описание (EN)
A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). As part of the stateful traffic processing on SRX Series devices flows are being established, and removed when not needed anymore. During the removal process the timeout of a flow should be set to 3 seconds and consequentially the flow should be removed shortly after. Due to a race condition occurring when setting the timeout there is a chance (the exact conditions are outside the attackers control) that the timeout is instead set to a very high value of larger than 10,000 seconds: user@host> show security flow session | match timeout Session ID: 98784248524, Policy name: PROD-FLOW/4, HA State: Active, Timeout: 85250, Session State: Valid This will lead to an accumulation of flows which can be observed by an ever-increasing value of invalidated sessions in the output of 'show security flow session summary': user@host> show security flow session summary | match invalid Invalidated sessions: 216931These sessions can't be cleared manually with the 'clear security flow session' command, which will either lead to forwarding to stop (and the system needs to be manually recovered with a reboot) or to a flowd core and automatic reboot. This issue affects Junos OS on SRX Series: * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S1, 24.4R2-S2, * 25.2 versions before 25.2R1-S2, 25.2R2. This issue does not affect releases earlier than 24.2R1;
Характеристики атаки
Последствия
Строка CVSS v4.0
Тип уязвимости (CWE)
Уязвимые продукты 34
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Juniper Junos
cpe:2.3:o:juniper:junos:24.2:-:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:24.2:r1:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:24.2:r1-s1:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:24.2:r1-s2:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:24.2:r2:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:24.2:r2-s1:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:24.2:r2-s2:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:24.4:-:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:24.4:r1:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:24.4:r1-s2:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:24.4:r1-s3:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:24.4:r2:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:25.2:-:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:25.2:r1:*:*:*:*:*:*
|
— | — |
|
Juniper Junos
cpe:2.3:o:juniper:junos:25.2:r1-s1:*:*:*:*:*:*
|
— | — |
|
Juniper Srx1500
cpe:2.3:h:juniper:srx1500:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx1600
cpe:2.3:h:juniper:srx1600:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx2300
cpe:2.3:h:juniper:srx2300:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx300
cpe:2.3:h:juniper:srx300:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx320
cpe:2.3:h:juniper:srx320:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx340
cpe:2.3:h:juniper:srx340:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx345
cpe:2.3:h:juniper:srx345:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx380
cpe:2.3:h:juniper:srx380:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx400
cpe:2.3:h:juniper:srx400:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx4100
cpe:2.3:h:juniper:srx4100:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx4120
cpe:2.3:h:juniper:srx4120:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx4200
cpe:2.3:h:juniper:srx4200:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx4300
cpe:2.3:h:juniper:srx4300:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx440
cpe:2.3:h:juniper:srx440:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx4600
cpe:2.3:h:juniper:srx4600:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx4700
cpe:2.3:h:juniper:srx4700:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx5400
cpe:2.3:h:juniper:srx5400:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx5600
cpe:2.3:h:juniper:srx5600:-:*:*:*:*:*:*:*
|
— | — |
|
Juniper Srx5800
cpe:2.3:h:juniper:srx5800:-:*:*:*:*:*:*:*
|
— | — |