CVE-2024-30391
Last modified
CVE-2024-30391 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A Missing Authentication for Critical Function vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated network-based attacker to cause limited impact to the integrity or availability of the device. If a device is configured with IPsec authentication algorithm hmac-sha-384 or hmac-sha-512, tunnels are established normally but for traffic traversing the tunnel no authentication information is sent with the encrypted data on egress, and no authentication information is expected on ingress. So if the peer is an unaffected device transit traffic is going to fail in both directions. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
A Missing Authentication for Critical Function vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated network-based attacker to cause limited impact to the integrity or availability of the device. If a device is configured with IPsec authentication algorithm hmac-sha-384 or hmac-sha-512, tunnels are established normally but for traffic traversing the tunnel no authentication information is sent with the encrypted data on egress, and no authentication information is expected on ingress. So if the peer is an unaffected device transit traffic is going to fail in both directions. If the peer is an also affected device transit traffic works, but without authentication, and configuration and CLI operational commands indicate authentication is performed. This issue affects Junos OS: * All versions before 20.4R3-S7, * 21.1 versions before 21.1R3, * 21.2 versions before 21.2R2-S1, 21.2R3, * 21.3 versions before 21.3R1-S2, 21.3R2.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | < 20.4 |
| Juniper | Junos | 20.4 |
| Juniper | Junos | 21.1 |
| Juniper | Junos | 21.2 |
| Juniper | Junos | 21.3 |
References
- http://supportportal.juniper.net/JSA79188Vendor Advisory
- http://supportportal.juniper.net/JSA79188Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-30391?
How severe is CVE-2024-30391?
How do I fix CVE-2024-30391?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-30386A Use-After-Free vulnerability in the Layer 2 Address Learni…7.1
- CVE-2024-30387A Missing Synchronization vulnerability in the Packet Forwar…7.1
- CVE-2024-30388An Improper Isolation or Compartmentalization vulnerability …7.1
- CVE-2024-30389An Incorrect Behavior Order vulnerability in the Packet Forw…6.9
- CVE-2024-3039A vulnerability classified as critical has been found in Sha…9.8
- CVE-2024-30390An Improper Restriction of Excessive Authentication Attempts…6.9
- CVE-2024-30392A Stack-based Buffer Overflow vulnerability in Flow Processi…8.7
- CVE-2024-30394A Stack-based Buffer Overflow vulnerability in the Routing P…8.7
- CVE-2024-30395An Improper Validation of Specified Type of Input vulnerabil…8.7
- CVE-2024-30397An Improper Check for Unusual or Exceptional Conditions vuln…8.7
- CVE-2024-30398An Improper Restriction of Operations within the Bounds of a…8.7
- CVE-2024-3040A vulnerability, which was classified as critical, was found…9.8
Are you affected by CVE-2024-30391?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
