CVE-2024-21610

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 12, 2024
Updated: May 16, 2024
CWE ID 755

Summary

CVE-2024-21610 is an Improper Handling of Exceptional Conditions vulnerability affecting Juniper Networks Junos OS on MX Series. This issue allows authenticated, low-privileged attackers to cause a limited Denial of Service (DoS) by exploiting a vulnerability in the Class of Service daemon (cosd). In a scaled subscriber scenario, specific commands handled by cosd on behalf of mgd cause the respective mgd processes to get stuck, leading to a denial of service for SSH or telnet sessions when connection limits are reached. Affected versions include all releases earlier than 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S3, 22.3R3-S2, 22.4R3, and 23.2R1-S2, 23.2R2. The vulnerability can be detected by executing the command "show system processes extensive | match mgd | match sbwait" to identify stuck mgd processes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Juniper Junos

Affected Vendors

  • Juniper Networks