PT-2024-3102 · Juniper Networks · Junos
Published
2024-04-10
·
Updated
2024-05-16
·
CVE-2024-30398
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Junos OS versions 21.2 before 21.2R3-S7
Junos OS versions 21.4 before 21.4R3-S6
Junos OS versions 22.1 before 22.1R3-S5
Junos OS versions 22.2 before 22.2R3-S3
Junos OS versions 22.3 before 22.3R3-S2
Junos OS versions 22.4 before 22.4R3
Junos OS versions 23.2 before 23.2R1-S2, 23.2R2
Description
The issue is related to an Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS. This allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS) by sending specific traffic to a SRX4600 device. The error in internal packet handling results in a consistent rise in CPU memory utilization, leading to packet drops and eventually the PFE crashes. A manual reboot of the PFE is required to restore the device to its original state.
Recommendations
For Junos OS versions 21.2 before 21.2R3-S7, update to version 21.2R3-S7 or later.
For Junos OS versions 21.4 before 21.4R3-S6, update to version 21.4R3-S6 or later.
For Junos OS versions 22.1 before 22.1R3-S5, update to version 22.1R3-S5 or later.
For Junos OS versions 22.2 before 22.2R3-S3, update to version 22.2R3-S3 or later.
For Junos OS versions 22.3 before 22.3R3-S2, update to version 22.3R3-S2 or later.
For Junos OS versions 22.4 before 22.4R3, update to version 22.4R3 or later.
For Junos OS versions 23.2 before 23.2R1-S2, 23.2R2, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the vulnerable Packet Forwarding Engine (PFE) to minimize the risk of exploitation.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos