CVE-2024-21611

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 12, 2024
Updated: Jan 18, 2024
CWE ID 401

Summary

CVE-2024-21611 is a Denial of Service vulnerability affecting the Routing Protocol Daemon (rpd) in Juniper Networks Junos OS and Junos OS Evolved. An unauthenticated attacker can exploit a memory leak in rpd caused by route churn in Juniper Flow Monitoring scenarios, resulting in a crash and restart of the daemon. This issue impacts Junos OS versions 21.4, 22.1, and 22.2, as well as their corresponding Junos OS Evolved versions. Versions earlier than 21.4R1 for both Junos OS and Junos OS Evolved are not affected. To check thread level memory utilization for affected areas, use the command 'show task memory detail | match so\_in'.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Juniper Junos
  • Juniper Junos Os Evolved

Affected Vendors

  • Juniper Networks