CVE-2024-39515

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 9, 2024
Updated: Oct 10, 2024
CWE ID 1288

Summary

CVE-2024-39515 is a Denial of Service (DoS) vulnerability affecting Juniper Networks Junos OS and Junos OS Evolved. An unauthenticated attacker can send a malformed BGP packet to cause the routing protocol daemon (rpd) to crash and restart, resulting in a sustained DoS condition. This vulnerability impacts systems with BGP traceoptions enabled and requires a BGP session to be already established. Both IPv4 and IPv6 are affected, and versions of Junos OS and Junos OS Evolved prior to certain releases are vulnerable. iBGP and eBGP sessions are impacted, and in some cases, rpd may fail to restart, requiring a manual restart.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share