PT-2024-5566 · Juniper Networks · Junos+1
Published
2024-07-10
·
Updated
2024-07-11
·
CVE-2024-39554
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Junos OS versions 21.1 through 23.2 before 23.2R2
Junos OS Evolved versions 21.1-EVO through 23.2-EVO before 23.2R2-EVO
Description
The issue is related to a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved. This vulnerability allows an unauthenticated, network-based attacker to inject incremental routing updates when BGP multipath is enabled, causing rpd to crash and restart, resulting in a Denial of Service (DoS). The successful exploitation of this vulnerability is outside the attacker's control, but continued receipt and processing of this packet may create a sustained Denial of Service (DoS) condition.
Recommendations
For Junos OS versions 21.1 through 23.2 before 23.2R2, update to version 23.2R2 or later to resolve the issue.
For Junos OS Evolved versions 21.1-EVO through 23.2-EVO before 23.2R2-EVO, update to version 23.2R2-EVO or later to resolve the issue.
As a temporary workaround, consider disabling BGP multipath to minimize the risk of exploitation.
Fix
DoS
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos
Junos Evolved