Incorrect comparison in Junos OS Evolved - CVE-2024-39534

 

Incorrect comparison in Junos OS Evolved - CVE-2024-39534

Published: October 11, 2024


Vulnerability identifier: #VU98393
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-39534
CWE-ID: CWE-697
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The vulnerability exists due to  incorrect comparison error in the local address verification API. A remote non-authenticated attacker can create sessions or send traffic to the device using the network and broadcast address of the subnet assigned to an interface.


Affected software

Junos OS Evolved

How to mitigate CVE-2024-39534

Install updates from vendor's website.

Junos OS Evolved - addressed in versions 21.4R3-S8-EVO, 22.2R3-S4-EVO, 22.3R3-S4-EVO

External References

Related Security Bulletins