PT-2024-5542 · Juniper Networks · Junos
Published
2024-06-25
·
Updated
2024-07-11
·
CVE-2024-39518
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Junos OS versions 21.2R3-S5 through 21.2R3-S7
Junos OS versions 21.4R3-S4 through 21.4R3-S6
Junos OS versions 22.2R3 through 22.2R3-S4
Junos OS versions 22.3R2 through 22.3R3-S2
Junos OS versions 22.4R1 through 22.4R3
Junos OS versions 23.2R1 through 23.2R2
Description
A Heap-based Buffer Overflow vulnerability in the telemetry sensor process of Juniper Networks Junos OS causes a steady increase in memory utilization, ultimately leading to a Denial of Service. This issue occurs when the device is subscribed to a specific subscription on Junos Telemetry Interface, resulting in a slow memory leak that consumes all resources and makes the device unresponsive. The Heap memory utilization can be monitored using the command
show system processes extensive, and the memory utilization of the specific sensor can be monitored using the command show system info | match sensord.Recommendations
For versions 21.2R3-S5 through 21.2R3-S7, update to version 21.2R3-S7 or later.
For versions 21.4R3-S4 through 21.4R3-S6, update to version 21.4R3-S6 or later.
For versions 22.2R3 through 22.2R3-S4, update to version 22.2R3-S4 or later.
For versions 22.3R2 through 22.3R3-S2, update to version 22.3R3-S2 or later.
For versions 22.4R1 through 22.4R3, update to version 22.4R3 or later.
For versions 23.2R1 through 23.2R2, update to version 23.2R2 or later.
Fix
DoS
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos