PT-2024-1114 · Juniper Networks · Junos

Published

2024-01-10

·

Updated

2024-01-18

·

CVE-2024-21606

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Junos OS versions earlier than 20.4R3-S8 Junos OS versions 21.2 earlier than 21.2R3-S6 Junos OS versions 21.3 earlier than 21.3R3-S5 Junos OS versions 21.4 earlier than 21.4R3-S5 Junos OS versions 22.1 earlier than 22.1R3-S3 Junos OS versions 22.2 earlier than 22.2R3-S3 Junos OS versions 22.3 earlier than 22.3R3-S1 Junos OS versions 22.4 earlier than 22.4R2-S2, 22.4R3
Description A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). In a remote access VPN scenario, if a "tcp-encap-profile" is configured and a sequence of specific packets is received, a flowd crash and restart will be observed.
Recommendations For versions earlier than 20.4R3-S8, update to 20.4R3-S8 or later. For versions 21.2 earlier than 21.2R3-S6, update to 21.2R3-S6 or later. For versions 21.3 earlier than 21.3R3-S5, update to 21.3R3-S5 or later. For versions 21.4 earlier than 21.4R3-S5, update to 21.4R3-S5 or later. For versions 22.1 earlier than 22.1R3-S3, update to 22.1R3-S3 or later. For versions 22.2 earlier than 22.2R3-S3, update to 22.2R3-S3 or later. For versions 22.3 earlier than 22.3R3-S1, update to 22.3R3-S1 or later. For versions 22.4 earlier than 22.4R2-S2, 22.4R3, update to 22.4R2-S2, 22.4R3 or later. As a temporary workaround, consider disabling the "tcp-encap-profile" configuration until a patch is available.

Fix

DoS

Double Free

Weakness Enumeration

Related Identifiers

BDU:2024-00397
CVE-2024-21606

Affected Products

Junos