Missing Synchronization in Juniper Junos OS - CVE-2024-30387
Published: April 12, 2024
Juniper Junos OS
Juniper Networks, Inc.
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a missing synchronization error in the Packet Forwarding Engine (PFE). A remote authenticated attacker on the local network can cause a Denial-of-Service (DoS).
If an interface flaps while the system gathers statistics on that interface, two processes simultaneously access a shared resource which leads to a PFE crash and restart.