CVE-2024-21595

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 12, 2024
Updated: Jan 18, 2024
CWE ID 1286

Summary

CVE-2024-21595 is aDenial of Service (DoS) vulnerability affecting the Packet Forwarding Engine (PFE) in Juniper Networks Junos OS. Specific ICMP traffic can cause a deadlock in the PFE, rendering the device unresponsive. This issue is only observed in EX4100, EX4400, EX4600, and QFX5000 Series devices. Versions of Junos OS included in the affected range are 21.4R3 earlier than 21.4R3-S4, 22.1R3 earlier than 22.1R3-S3, 22.2R2 earlier than 22.2R3-S1, 22.3 versions earlier than 22.3R2-S2 and 22.3R3, 22.4 versions earlier than 22.4R2, and 23.1 versions earlier than 23.1R2. An unauthenticated attacker can trigger this DoS condition by sending a high rate of specific ICMP packets to the device. Users are advised to upgrade their Junos OS to a non-affected version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Juniper Junos

Affected Vendors

  • Juniper Networks