Improper Check or Handling of Exceptional Conditions in Junos OS Evolved - CVE-2024-47489

 

Improper Check or Handling of Exceptional Conditions in Junos OS Evolved - CVE-2024-47489

Published: October 11, 2024


Vulnerability identifier: #VU98395
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47489
CWE-ID: CWE-703
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices. Receipt of specific transit protocol packets is incorrectly processed by the Routing Engine (RE), filling up the DDoS protection queue which is shared between routing protocols. This influx of transit protocol packets causes DDoS protection violations, resulting in protocol flaps which can affect connectivity to networking devices.


Affected software

Junos OS Evolved

How to mitigate CVE-2024-47489

Install updates from vendor's website.

Junos OS Evolved - addressed in versions 21.4R3-S8-EVO, 22.2R3-S4-EVO, 22.3R3-S4-EVO, 22.4R3-S3-EVO, 23.2R2-EVO, 23.4R1-S1-EVO, 23.4R2-EVO, 24.2R2-EVO, 24.4R1-EVO

External References

Related Security Bulletins