CVE-2024-21609
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-21609 is a vulnerability affecting the IKE daemon (iked) in Juniper Networks Junos OS on MX Series with SPC3, and SRX Series. An administratively adjacent attacker who can establish IPsec tunnels can cause a Denial of Service (DoS) by exploiting a Missing Release of Memory after Effective Lifetime issue. The vulnerability is triggered when specific IPsec parameters are received from the peer, resulting in a memory leak during SA rekey. This eventually leads to an iked process crash and restart. The memory consumption of the iked process can be checked using the 'show system processes extensive' command. This vulnerability affects multiple versions of Juniper Networks Junos OS, including versions earlier than 20.4R3-S9, 21.2 versions earlier than 21.2R3-S7, 21.3 versions earlier than 21.3R3-S5, 21.4 versions earlier than 21.4R3-S4, 22.1 versions earlier than 22.1R3-S3, 22.2 versions earlier than 22.2R3-S2, 22.3 versions earlier than 22.3R3, and 23.2 versions earlier than 23.2R1-S2, 23.2R2.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Juniper Junos
Affected Vendors
- Juniper Networks