CVE-2024-21597

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 12, 2024
Updated: Jan 19, 2024
CWE ID 668

Summary

CVE-2024-21597 is an Exposure of Resource to Wrong Sphere vulnerability affecting the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series. This issue allows unauthenticated, network-based attackers to bypass intended access restrictions, specifically in an Abstracted Fabric (AF) scenario where routing-instances (RI) are configured. Traffic destined to the device, which should be filtered by the lo0 firewall, can bypass these filters when received in the wrong RI context. Affected versions include all those earlier than 20.4R3-S9, 21.2 versions earlier than 21.2R3-S3, 21.4 versions earlier than 21.4R3-S5, 22.1 versions earlier than 22.1R3, 22.2 versions earlier than 22.2R3, and 22.3 versions earlier than 22.3R2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Juniper Junos

Affected Vendors

  • Juniper Networks