PT-2024-5566 · Juniper Networks · Junos+1

Published

2024-07-10

·

Updated

2024-07-11

·

CVE-2024-39554

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Junos OS versions 21.1 through 23.2 before 23.2R2 Junos OS Evolved versions 21.1-EVO through 23.2-EVO before 23.2R2-EVO
Description The issue is related to a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved. This vulnerability allows an unauthenticated, network-based attacker to inject incremental routing updates when BGP multipath is enabled, causing rpd to crash and restart, resulting in a Denial of Service (DoS). The successful exploitation of this vulnerability is outside the attacker's control, but continued receipt and processing of this packet may create a sustained Denial of Service (DoS) condition.
Recommendations For Junos OS versions 21.1 through 23.2 before 23.2R2, update to version 23.2R2 or later to resolve the issue. For Junos OS Evolved versions 21.1-EVO through 23.2-EVO before 23.2R2-EVO, update to version 23.2R2-EVO or later to resolve the issue. As a temporary workaround, consider disabling BGP multipath to minimize the risk of exploitation.

Fix

DoS

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2024-06245
CVE-2024-39554

Affected Products

Junos
Junos Evolved