CVE-2024-21609

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 12, 2024
Updated: May 16, 2024
CWE ID 401

Summary

CVE-2024-21609 is a vulnerability affecting the IKE daemon (iked) in Juniper Networks Junos OS on MX Series with SPC3, and SRX Series. An administratively adjacent attacker who can establish IPsec tunnels can cause a Denial of Service (DoS) by exploiting a Missing Release of Memory after Effective Lifetime issue. The vulnerability is triggered when specific IPsec parameters are received from the peer, resulting in a memory leak during SA rekey. This eventually leads to an iked process crash and restart. The memory consumption of the iked process can be checked using the 'show system processes extensive' command. This vulnerability affects multiple versions of Juniper Networks Junos OS, including versions earlier than 20.4R3-S9, 21.2 versions earlier than 21.2R3-S7, 21.3 versions earlier than 21.3R3-S5, 21.4 versions earlier than 21.4R3-S4, 22.1 versions earlier than 22.1R3-S3, 22.2 versions earlier than 22.2R3-S2, 22.3 versions earlier than 22.3R3, and 23.2 versions earlier than 23.2R1-S2, 23.2R2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Juniper Junos

Affected Vendors

  • Juniper Networks