CVE-2024-30409
Last modified
CVE-2024-30409 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. An Improper Check for Unusual or Exceptional Conditions vulnerability in telemetry processing of Juniper Networks Junos OS and Junos OS Evolved allows a network-based authenticated attacker to cause the forwarding information base telemetry daemon (fibtd) to crash, leading to a limited Denial of Service. This issue affects Juniper Networks Junos OS: * from 22.1 before 22.1R1-S2, 22.1R2. Junos OS Evolved: * from 22.1 before 22.1R1-S2-EVO, 22.1R2-EVO.. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in telemetry processing of Juniper Networks Junos OS and Junos OS Evolved allows a network-based authenticated attacker to cause the forwarding information base telemetry daemon (fibtd) to crash, leading to a limited Denial of Service. This issue affects Juniper Networks Junos OS: * from 22.1 before 22.1R1-S2, 22.1R2. Junos OS Evolved: * from 22.1 before 22.1R1-S2-EVO, 22.1R2-EVO.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | 22.1 |
| Juniper | Junos Os Evolved | 22.1 |
References
- https://supportportal.juniper.net/JSA79099Vendor Advisory
- https://supportportal.juniper.net/JSA79099Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-30409?
How severe is CVE-2024-30409?
How do I fix CVE-2024-30409?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-30401An Out-of-bounds Read vulnerability in the advanced forwardi…8.2
- CVE-2024-30402An Improper Check for Unusual or Exceptional Conditions vuln…5.3
- CVE-2024-30403A NULL Pointer Dereference vulnerability in the Packet Forwa…7.1
- CVE-2024-30405An Incorrect Calculation of Buffer Size vulnerability in Jun…8.7
- CVE-2024-30406A Cleartext Storage in a File on Disk vulnerability in Junip…6.7
- CVE-2024-30407The Use of a Hard-coded Cryptographic Key vulnerability in J…9.2
- CVE-2024-3041A vulnerability has been found in Netentsec NS-ASG Applicati…9.8
- CVE-2024-30410An Incorrect Behavior Order in the routing engine (RE) of Ju…6.9
- CVE-2024-30413Vulnerability of improper permission control in the window m…7.5
- CVE-2024-30414Command injection vulnerability in the AccountManager module…7.5
- CVE-2024-30415Vulnerability of improper permission control in the window m…9.1
- CVE-2024-30416Use After Free (UAF) vulnerability in the underlying driver …7.5
Are you affected by CVE-2024-30409?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
