CyberzSOC

Publication detail
← Back to advisories & guidance

2024-038: Critical vulnerabilities in Junos OS and Junos OS Evolved ↗ source

April 16, 2024 CERT-EU Advisory

Summary

These vulnerabilities could allow remote attackers to execute arbitrary code, cause denial of service, or leak sensitive information. It is strongly advised to update affected systems to the latest versions to mitigate these risks. The vulnerability CVE-2023-38545, with a CVSS score of 9.8, is due to a heap-based buffer overflow in SOCKS5 proxy handshake in curl that could allow remote attackers to execute The vulnerabilities CVE-2023-23914 and CVE-2023-23915, respectively with CVSS scores of 9.1 and 6.5, are caused by HSTS mechanism failures, and would allow transmission of sensitive information over unencrypted channels under certain conditions. The vulnerability CVE-2020-8285, with a CVSS score of 7.5, is due to improper certificate The vulnerability CVE-2020-8286, with a CVSS score of 7.5, is due to improper handling of network responses would cause denial of service conditions. The vulnerabilities CVE-2018-1000120 and CVE-2018-1000122, respectively with CVSS scores of 9.8 and 9.1, are older buffer overflow and buffer over-read vulnerabilities affecting older versions of curl, and could cause denial of service, information leakage, or worse.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2023-23914 9.1 Critical n/a https://github.com/curl/curl A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs a…
CVE-2023-38545 8.8 High curl curl This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy …
CVE-2020-8285 7.5 High n/a https://github.com/curl/curl curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
CVE-2023-23915 6.5 Medium n/a https://github.com/curl/curl A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly whe…
CVE-2018-1000120 — n/a n/a A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or …
CVE-2018-1000122 — n/a n/a A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of serv…
CVE-2020-8286 — n/a https://github.com/curl/curl curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.