Improper Check or Handling of Exceptional Conditions in Junos OS Evolved and Junos OS - CVE-2024-39525

 

Improper Check or Handling of Exceptional Conditions in Junos OS Evolved and Junos OS - CVE-2024-39525

Published: October 11, 2024


Vulnerability identifier: #VU98392
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-39525
CWE-ID: CWE-703
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper handling of exceptional conditions in the routing protocol daemon (rpd) when BGP nexthop traceoptions is enabled. A remote attacker can send a specific BGP packet to cause rpd to crash and restart.

This issue affects iBGP and eBGP, and both IPv4 and IPv6 are affected by this vulnerability.


Affected software

Junos OS Evolved
Junos OS

How to mitigate CVE-2024-39525

Install updates from vendor's website.

Junos OS Evolved - addressed in versions 21.2R3-S8-EVO, 21.4R3-S8-EVO, 22.2R3-S4-EVO, 22.3R3-S4-EVO, 22.4R3-S3-EVO, 23.2R2-S1-EVO, 23.4R2-EVO, 24.2R1-EVO
Junos OS - addressed in versions 21.2R3-S8, 21.4R3-S8, 22.2R3-S4, 22.3R3-S4, 22.4R3-S3, 23.2R2-S1, 23.4R2, 24.2R1

External References

Related Security Bulletins