Home

Description

An Improper Check or Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). An attacker can send specific traffic to the device, which causes the rpd to crash and restart. Continued receipt of this traffic will result in a sustained DoS condition. This issue only affects devices with an EVPN-VPWS instance with IGMP-snooping enabled. This issue affects Junos OS: * All versions before 20.4R3-S10,  * from 21.4 before 21.4R3-S6,  * from 22.1 before 22.1R3-S5,  * from 22.2 before 22.2R3-S3,  * from 22.3 before 22.3R3-S2,  * from 22.4 before 22.4R3,  * from 23.2 before 23.2R2; Junos OS Evolved: * All versions before 20.4R3-S10-EVO,  * from 21.4-EVO before 21.4R3-S6-EVO,  * from 22.1-EVO before 22.1R3-S5-EVO,  * from 22.2-EVO before 22.2R3-S3-EVO,  * from 22.3-EVO before 22.3R3-S2-EVO,  * from 22.4-EVO before 22.4R3-EVO,  * from 23.2-EVO before 23.2R2-EVO.

PUBLISHED Reserved 2024-06-25 | Published 2024-07-10 | Updated 2024-08-02 | Assigner juniper




MEDIUM: 6.5CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

HIGH: 7.1CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L

Problem types

CWE-703 Improper Check or Handling of Exceptional Conditions

Product status

Default status
unaffected

Any version before 20.4R3-S10
affected

21.4 (semver) before 21.4R3-S6
affected

22.1 (semver) before 22.1R3-S5
affected

22.2 (semver) before 22.2R3-S3
affected

22.3 (semver) before 22.3R3-S2
affected

22.4 (semver) before 22.4R3
affected

23.2 (semver) before 23.2R2
affected

Default status
unaffected

Any version before 20.4R3-S10-EVO
affected

21.4-EVO (semver) before 21.4R3-S6-EVO
affected

22.1-EVO (semver) before 22.1R3-S5-EVO
affected

22.2-EVO (semver) before 22.2R3-S3-EVO
affected

22.3-EVO (semver) before 22.3R3-S2-EVO
affected

22.4-EVO (semver) before 22.4R3-EVO
affected

23.2-EVO (semver) before 23.2R2-EVO
affected

References

supportportal.juniper.net/JSA82980 vendor-advisory

cve.org (CVE-2024-39514)

nvd.nist.gov (CVE-2024-39514)

Download JSON