Improper Check or Handling of Exceptional Conditions in Junos OS Evolved and Junos OS - CVE-2024-39525
Published: October 11, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of exceptional conditions in the routing protocol daemon (rpd) when BGP nexthop traceoptions is enabled. A remote attacker can send a specific BGP packet to cause rpd to crash and restart.
This issue affects iBGP and eBGP, and both IPv4 and IPv6 are affected by this vulnerability.
Affected software
Junos OS
How to mitigate CVE-2024-39525
Junos OS - addressed in versions 21.2R3-S8, 21.4R3-S8, 22.2R3-S4, 22.3R3-S4, 22.4R3-S3, 23.2R2-S1, 23.4R2, 24.2R1