Deadlock Vulnerability in Juniper Networks Junos OS on SRX Series Can Cause Denial of Service
CVE-2024-47506

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 October 2024

Summary

A Deadlock vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).

When a large amount of traffic is processed by ATP Cloud inspection, a deadlock can occur which will result in a PFE crash and restart. Whether the crash occurs, depends on system internal timing that is outside the attackers control.

This issue affects Junos OS on SRX Series:

  • All versions before 21.3R3-S1,
  • 21.4 versions before 21.4R3,
  • 22.1 versions before 22.1R2,
  • 22.2 versions before 22.2R1-S2, 22.2R2.

Affected Version(s)

Junos OS SRX Series 0 < 21.3R3-S1

Junos OS SRX Series 21.4 < 21.4R3

Junos OS SRX Series 22.1 < 22.1R2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.