PT-2024-1130 · Juniper Networks · Junos

Published

2024-01-10

·

Updated

2024-01-19

·

CVE-2024-21599

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos OS on MX Series versions earlier than 20.4R3-S3 Juniper Networks Junos OS on MX Series version 21.1 versions earlier than 21.1R3-S4 Juniper Networks Junos OS on MX Series version 21.2 versions earlier than 21.2R3 Juniper Networks Junos OS on MX Series version 21.3 versions earlier than 21.3R2-S1, 21.3R3 Juniper Networks Junos OS on MX Series version 21.4 versions earlier than 21.4R2 Juniper Networks Junos OS on MX Series version 22.1 versions earlier than 22.1R2
Description A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). If an MX Series device receives PTP packets on an MPC3E that doesn't support PTP, this causes a memory leak which will result in unpredictable behavior and ultimately in an MPC crash and restart. To monitor for this issue, use the following FPC vty level commands: "show heap" to check for an increase in "LAN buffer" utilization and "show clksync ptp nbr-upd-info" to check for a non-zero "Pending PFEs" counter.
Recommendations For versions earlier than 20.4R3-S3, update to version 20.4R3-S3 or later. For version 21.1, update to version 21.1R3-S4 or later. For version 21.2, update to version 21.2R3 or later. For version 21.3, update to version 21.3R2-S1 or 21.3R3 or later. For version 21.4, update to version 21.4R2 or later. For version 22.1, update to version 22.1R2 or later. As a temporary workaround, consider restricting the reception of PTP packets on MPC3E devices that do not support PTP to minimize the risk of exploitation.

Fix

DoS

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00443
CVE-2024-21599

Affected Products

Junos