CVE-2024-47501

CVSS 3.1 Score 5.5 of 10 (medium)

Attack Complexity low
Availability high
Privileges Required low
Confidentiality none
Integrity none
Scope unchanged

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 476

Summary

CVE-2024-47501 is a NULL Pointer Dereference vulnerability affecting the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific MX and EX series devices. This issue lets a locally authenticated attacker with low privileges induce a Denial of Service (DoS) condition. In VPLS or Junos Fusion environments, executing certain show commands can lead to crashes and restart of all FPCs hosting VPLS sessions or connecting to satellites. Impacted devices include MX304, MX with MPC10/11/LC9600, and EX9200 with EX9200-15C. Affected Junos versions are all before 21.2R3-S1, 21.3 versions before 21.3R3, and 21.4 versions before 21.4R2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Juniper Junos

Affected Vendors

  • Juniper Networks