CVE-2024-47489
Last modified
CVE-2024-47489 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices allows an unauthenticated, network based attacker sending specific transit protocol traffic to cause a partial Denial of Service (DoS) to downstream devices. Receipt of specific transit protocol packets is incorrectly processed by the Routing Engine (RE), filling up the DDoS protection queue which is shared between routing protocols. This influx of transit protocol packets causes DDoS protection violations, resulting in protocol flaps which can affect connectivity to networking devices. This issue affects both IPv4 and IPv6. This issue does not require any specific routing protocol to be configured or enabled. The following commands can be used to monitor the DDoS protection queue: labuser@re0> show evo-pfemand host pkt-stats labuser@re0> show host-path ddos all-policers This issue affects Junos OS Evolved: * All versions before 21.4R3-S8-EVO, * from 22.2 before 22.2R3-S4-EVO, * from 22.3 before 22.3R3-S4-EVO, * from 22.4 before 22.4R3-S3-EVO, * from 23.2 before 23.2R2-EVO, * from 23.4 before 23.4R1-S1-EVO, 23.4R2-EVO, * from 24.2 before 24.2R2-EVO.. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices allows an unauthenticated, network based attacker sending specific transit protocol traffic to cause a partial Denial of Service (DoS) to downstream devices. Receipt of specific transit protocol packets is incorrectly processed by the Routing Engine (RE), filling up the DDoS protection queue which is shared between routing protocols. This influx of transit protocol packets causes DDoS protection violations, resulting in protocol flaps which can affect connectivity to networking devices. This issue affects both IPv4 and IPv6. This issue does not require any specific routing protocol to be configured or enabled. The following commands can be used to monitor the DDoS protection queue: labuser@re0> show evo-pfemand host pkt-stats labuser@re0> show host-path ddos all-policers This issue affects Junos OS Evolved: * All versions before 21.4R3-S8-EVO, * from 22.2 before 22.2R3-S4-EVO, * from 22.3 before 22.3R3-S4-EVO, * from 22.4 before 22.4R3-S3-EVO, * from 23.2 before 23.2R2-EVO, * from 23.4 before 23.4R1-S1-EVO, 23.4R2-EVO, * from 24.2 before 24.2R2-EVO.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:A/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos Os Evolved | < 21.4 |
| Juniper | Junos Os Evolved | 21.4 |
| Juniper | Junos Os Evolved | 22.2 |
| Juniper | Junos Os Evolved | 22.3 |
| Juniper | Junos Os Evolved | 22.4 |
| Juniper | Junos Os Evolved | 23.2 |
| Juniper | Junos Os Evolved | 23.4 |
| Juniper | Junos Os Evolved | 24.2 |
References
- https://supportportal.juniper.net/Permissions Required
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-47489?
How severe is CVE-2024-47489?
How do I fix CVE-2024-47489?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-47481Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) …6.5
- CVE-2024-47483Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain…5.5
- CVE-2024-47484Dell Avamar, versions prior to 19.12 with patch 338905, excl…9.8
- CVE-2024-47485There is a CSV injection vulnerability in some HikCentral Ma…9.8
- CVE-2024-47486There is an XSS vulnerability in some HikCentral Master Lite…6.1
- CVE-2024-47487There is a SQL injection vulnerability in some HikCentral Pr…8.8
- CVE-2024-4749The wp-eMember WordPress plugin before 10.3.9 does not sanit…8.3
- CVE-2024-47490An Improper Restriction of Communication Channel to Intended…8.2
- CVE-2024-47491An Improper Handling of Exceptional Conditions vulnerability…8.2
- CVE-2024-47493A Missing Release of Memory after Effective Lifetime vulnera…7.1
- CVE-2024-47494A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerab…8.2
- CVE-2024-47495An Authorization Bypass Through User-Controlled Key vulnerab…8.4
Are you affected by CVE-2024-47489?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
