CVE-2024-47490

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 923

Summary

CVE-2024-47490 is a vulnerability affecting the Packet Forwarding Engine (PFE) in Juniper Networks Junos OS Evolved on ACX 7000 Series. This issue enables unauthenticated, remote attackers to cause a Denial of Service (DoS) by exploiting an Improper Restriction of Communication Channel to Intended Endpoints vulnerability. The vulnerability occurs when specific MPLS packets are internally forwarded to the Routing Engine (RE), causing resource exhaustion. The issue impacts multiple versions of Junos OS Evolved ACX 7000 Series, including but not limited to versions before 21.4R3-S9-EVO, 22.2-EVO before 22.2R3-S4-EVO, 22.3-EVO before 22.3R3-S3-EVO, 22.4-EVO before 22.4R3-S2-EVO, and 23.2-EVO before 23.2R2-EVO, as well as 23.4-EVO before 23.4R1-S1-EVO and 23.4R2-EVO.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share