#VU85279 Exposure of resource to wrong sphere in Juniper Junos OS - CVE-2024-21597
Published: January 10, 2024
Juniper Junos OS
Juniper Networks, Inc.
Description
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The vulnerability exists due to exposure of resource to wrong sphere error in the Packet Forwarding Engine (PFE). A remote non-authenticated attacker can bypass the intended access restrictions.
In an Abstracted Fabric (AF) scenario if routing-instances (RI) are configured, specific valid traffic destined to the device can bypass the configured lo0 firewall filters as it's received in the wrong RI context.