PT-2024-5803 · Juniper Networks · Junos Evolved
Published
2024-07-10
·
Updated
2024-07-11
·
CVE-2024-39562
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS Evolved versions prior to 21.4R3-S7-EVO
Juniper Networks Junos OS Evolved 22.3-EVO versions prior to 22.3R2-S2-EVO, 22.3R3-S2-EVO
Juniper Networks Junos OS Evolved 22.4-EVO versions prior to 22.4R3-EVO
Juniper Networks Junos OS Evolved 23.2-EVO versions prior to 23.2R2-EVO
Description
A Missing Release of Resource after Effective Lifetime vulnerability in the xinetd process, responsible for spawning SSH daemon (sshd) instances, allows an unauthenticated network-based attacker to cause a Denial of Service (DoS) by blocking SSH access for legitimate users. This issue is triggered when a high rate of concurrent SSH requests are received and terminated in a specific way, causing xinetd to crash and leaving defunct sshd processes. Successful exploitation of this vulnerability blocks both SSH access and services which rely upon SSH, such as SFTP and Netconf over SSH. Administrators can monitor an increase in defunct sshd processes by utilizing the CLI command:
show system processes | match sshd.Recommendations
For versions prior to 21.4R3-S7-EVO, update to 21.4R3-S7-EVO or later.
For 22.3-EVO versions prior to 22.3R2-S2-EVO, 22.3R3-S2-EVO, update to 22.3R2-S2-EVO, 22.3R3-S2-EVO or later.
For 22.4-EVO versions prior to 22.4R3-EVO, update to 22.4R3-EVO or later.
For 23.2-EVO versions prior to 23.2R2-EVO, update to 23.2R2-EVO or later.
As a temporary workaround, consider monitoring the system for defunct sshd processes and manually restoring service when necessary.
Fix
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos Evolved