CVE-2024-21611
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-21611 is a Denial of Service vulnerability affecting the Routing Protocol Daemon (rpd) in Juniper Networks Junos OS and Junos OS Evolved. An unauthenticated attacker can exploit a memory leak in rpd caused by route churn in Juniper Flow Monitoring scenarios, resulting in a crash and restart of the daemon. This issue impacts Junos OS versions 21.4, 22.1, and 22.2, as well as their corresponding Junos OS Evolved versions. Versions earlier than 21.4R1 for both Junos OS and Junos OS Evolved are not affected. To check thread level memory utilization for affected areas, use the command 'show task memory detail | match so\_in'.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Juniper Junos
- Juniper Junos Os Evolved
Affected Vendors
- Juniper Networks