#VU98393 Incorrect comparison in Junos OS Evolved - CVE-2024-39534

 

#VU98393 Incorrect comparison in Junos OS Evolved - CVE-2024-39534

Published: October 11, 2024


Vulnerability identifier: #VU98393
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-39534
CWE-ID: CWE-697
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Junos OS Evolved
Software vendor:
Juniper Networks, Inc.

Description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The vulnerability exists due to  incorrect comparison error in the local address verification API. A remote non-authenticated attacker can create sessions or send traffic to the device using the network and broadcast address of the subnet assigned to an interface.


Remediation

Install updates from vendor's website.

External links