CVE-2024-30405
Last modified
CVE-2024-30405 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. An Incorrect Calculation of Buffer Size vulnerability in Juniper Networks Junos OS SRX 5000 Series devices using SPC2 line cards while ALGs are enabled allows an attacker sending specific crafted packets to cause a transit traffic Denial of Service (DoS). Continued receipt and processing of these specific packets will sustain the Denial of Service condition. This issue affects: Juniper Networks Junos OS SRX 5000 Series with SPC2 with ALGs enabled. * All versions earlier than 21.2R3-S7; * 21.4 versions earlier than 21.4R3-S6; * 22.1 versions earlier than 22.1R3-S5; * 22.2 versions earlier than 22.2R3-S3; * 22.3 versions earlier than 22.3R3-S2; * 22.4 versions earlier than 22.4R3; * 23.2 versions earlier than 23.2R2.. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
An Incorrect Calculation of Buffer Size vulnerability in Juniper Networks Junos OS SRX 5000 Series devices using SPC2 line cards while ALGs are enabled allows an attacker sending specific crafted packets to cause a transit traffic Denial of Service (DoS). Continued receipt and processing of these specific packets will sustain the Denial of Service condition. This issue affects: Juniper Networks Junos OS SRX 5000 Series with SPC2 with ALGs enabled. * All versions earlier than 21.2R3-S7; * 21.4 versions earlier than 21.4R3-S6; * 22.1 versions earlier than 22.1R3-S5; * 22.2 versions earlier than 22.2R3-S3; * 22.3 versions earlier than 22.3R3-S2; * 22.4 versions earlier than 22.4R3; * 23.2 versions earlier than 23.2R2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | < 21.2 |
| Juniper | Junos | 21.2 |
| Juniper | Junos | 21.4 |
| Juniper | Junos | 22.1 |
| Juniper | Junos | 22.2 |
| Juniper | Junos | 22.3 |
| Juniper | Junos | 22.4 |
| Juniper | Junos | 23.2 |
References
- https://supportportal.juniper.net/JSA79105Vendor Advisory
- https://supportportal.juniper.net/JSA79105Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-30405?
How severe is CVE-2024-30405?
How do I fix CVE-2024-30405?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-30397An Improper Check for Unusual or Exceptional Conditions vuln…8.7
- CVE-2024-30398An Improper Restriction of Operations within the Bounds of a…8.7
- CVE-2024-3040A vulnerability, which was classified as critical, was found…9.8
- CVE-2024-30401An Out-of-bounds Read vulnerability in the advanced forwardi…8.2
- CVE-2024-30402An Improper Check for Unusual or Exceptional Conditions vuln…5.3
- CVE-2024-30403A NULL Pointer Dereference vulnerability in the Packet Forwa…7.1
- CVE-2024-30406A Cleartext Storage in a File on Disk vulnerability in Junip…6.7
- CVE-2024-30407The Use of a Hard-coded Cryptographic Key vulnerability in J…9.2
- CVE-2024-30409An Improper Check for Unusual or Exceptional Conditions vuln…6.9
- CVE-2024-3041A vulnerability has been found in Netentsec NS-ASG Applicati…9.8
- CVE-2024-30410An Incorrect Behavior Order in the routing engine (RE) of Ju…6.9
- CVE-2024-30413Vulnerability of improper permission control in the window m…7.5
Are you affected by CVE-2024-30405?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
