CVE-2024-21594

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 12, 2024
Updated: Jan 18, 2024
CWE ID 122
CWE ID 787

Summary

CVE-2024-21594 is a Heap-based Buffer Overflow vulnerability in Juniper Networks Junos OS's Network Services Daemon (NSD) on SRX 5000 Series devices. This issue enables authenticated, low-privileged, local attackers to trigger a Denial of Service (DoS) by corrupting memory, causing the Flow Processing Daemon (flowd) to crash. The affected devices require the NSD process to be restarted to restore services. This vulnerability can be detected using the command 'user@host> request security policies check' and the log message 'Error: policies are out of sync for PFE node<number>.fpc<number>.pic<number>'. Juniper Networks Junos OS on SRX 5000 Series, including versions earlier than 20.4R3-S6, 21.1 versions earlier than 21.1R3-S5, 21.2 versions earlier than 21.2R3-S4, 21.3 versions earlier than 21.3R3-S3, 21.4 versions earlier than 21.4R3-S3, 22.1 versions earlier than 22.1R3-S1, 22.2 versions earlier than 22.2R3, and 22.3 versions earlier than 22.3R2, are all impacted.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share