SB2024101024 - Allocation of resources without limits or throttling in Junos OS Evolved



SB2024101024 - Allocation of resources without limits or throttling in Junos OS Evolved

Published: October 10, 2024

Security Bulletin ID SB2024101024
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Allocation of resources without limits or throttling (CVE-ID: CVE-2024-47502)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to allocation of resources without limits or throttling error in the kernel. A remote non-authenticated attacker can cause a Denial of Service (DoS).

In specific cases the state of TCP sessions that are terminated is not cleared, which over time leads to an exhaustion of resources, preventing new connections to the control plane from being established.

A continuously increasing number of connections shown by:user@host > show system connectionsis indicative of the problem.


Remediation

Install update from vendor's website.