PT-2024-3102 · Juniper Networks · Junos

CVE-2024-30398

·

Published

2024-04-10

·

Updated

2024-05-16

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Junos OS versions 21.2 before 21.2R3-S7 Junos OS versions 21.4 before 21.4R3-S6 Junos OS versions 22.1 before 22.1R3-S5 Junos OS versions 22.2 before 22.2R3-S3 Junos OS versions 22.3 before 22.3R3-S2 Junos OS versions 22.4 before 22.4R3 Junos OS versions 23.2 before 23.2R1-S2, 23.2R2
Description The issue is related to an Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS. This allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS) by sending specific traffic to a SRX4600 device. The error in internal packet handling results in a consistent rise in CPU memory utilization, leading to packet drops and eventually the PFE crashes. A manual reboot of the PFE is required to restore the device to its original state.
Recommendations For Junos OS versions 21.2 before 21.2R3-S7, update to version 21.2R3-S7 or later. For Junos OS versions 21.4 before 21.4R3-S6, update to version 21.4R3-S6 or later. For Junos OS versions 22.1 before 22.1R3-S5, update to version 22.1R3-S5 or later. For Junos OS versions 22.2 before 22.2R3-S3, update to version 22.2R3-S3 or later. For Junos OS versions 22.3 before 22.3R3-S2, update to version 22.3R3-S2 or later. For Junos OS versions 22.4 before 22.4R3, update to version 22.4R3 or later. For Junos OS versions 23.2 before 23.2R1-S2, 23.2R2, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the vulnerable Packet Forwarding Engine (PFE) to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03303
CVE-2024-30398

Affected Products

Junos