SB2024101112 - Incorrect comparison in Junos OS Evolved
Published: October 11, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Incorrect comparison (CVE-ID: CVE-2024-39534)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to incorrect comparison error in the local address verification API. A remote non-authenticated attacker can create sessions or send traffic to the device using the network and broadcast address of the subnet assigned to an interface.
Remediation
Install update from vendor's website.