PT-2024-1115 · Juniper Networks · Junos Evolved

Published

2024-01-10

·

Updated

2024-01-29

·

CVE-2024-21612

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS Evolved versions earlier than 21.2R3-S7-EVO Juniper Networks Junos OS Evolved version 21.3 versions earlier than 21.3R3-S5-EVO Juniper Networks Junos OS Evolved version 21.4 versions earlier than 21.4R3-S5-EVO Juniper Networks Junos OS Evolved version 22.1 versions earlier than 22.1R3-S4-EVO Juniper Networks Junos OS Evolved version 22.2 versions earlier than 22.2R3-S3-EVO Juniper Networks Junos OS Evolved version 22.3 versions earlier than 22.3R3-EVO Juniper Networks Junos OS Evolved version 22.4 versions earlier than 22.4R2-EVO, 22.4R3-EVO
Description An Improper Handling of Syntactically Invalid Structure issue in the Object Flooding Protocol (OFP) service allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS) by sending specific TCP packets to an open OFP port. This leads to the OFP crashing and a restart of the Routine Engine (RE), resulting in a sustained Denial of Service condition.
Recommendations For versions earlier than 21.2R3-S7-EVO, update to version 21.2R3-S7-EVO or later. For version 21.3, update to version 21.3R3-S5-EVO or later. For version 21.4, update to version 21.4R3-S5-EVO or later. For version 22.1, update to version 22.1R3-S4-EVO or later. For version 22.2, update to version 22.2R3-S3-EVO or later. For version 22.3, update to version 22.3R3-EVO or later. For version 22.4, update to version 22.4R2-EVO or 22.4R3-EVO or later. As a temporary workaround, consider restricting access to the OFP port to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-00398
CVE-2024-21612

Affected Products

Junos Evolved