We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-30403

Junos OS Evolved: When MAC learning happens, and an interface gets flapped, the PFE crashes



Description

A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When Layer 2 traffic is sent through a logical interface, MAC learning happens. If during this process, the interface flaps, an Advanced Forwarding Toolkit manager (evo-aftmand-bt) core is observed. This leads to a PFE restart. The crash reoccurs if the same sequence of events happens, which will lead to a sustained DoS condition. This issue affects Juniper Networks Junos OS Evolved 23.2-EVO versions earlier than 23.2R1-S1-EVO, 23.2R2-EVO.

Reserved 2024-03-26 | Published 2024-04-12 | Updated 2024-08-02 | Assigner juniper


MEDIUM: 6.5CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

HIGH: 7.1CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L

Problem types

CWE-476 NULL Pointer Dereference

Denial of Service (DoS)

Product status

Default status
unaffected

23.2-EVO before 23.2R1-S1-EVO, 23.2R2-EVO
affected

References

supportportal.juniper.net/JSA79181 vendor-advisory

www.first.org/cvss/calculator/4.0 technical-description

cve.org (CVE-2024-30403)

nvd.nist.gov (CVE-2024-30403)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-30403

Support options

Helpdesk Chat, Email, Knowledgebase