CVE-2024-47491

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Oct 11, 2024
Updated: Oct 17, 2024
CWE ID 755

Summary

CVE-2024-47491 is a Denial of Service (DoS) vulnerability affecting the Routing Protocol Daemon (rpd) in Juniper Networks Junos OS and Junos OS Evolved. An unauthenticated attacker can exploit this Improper Handling of Exceptional Conditions issue by sending a malformed BGP UPDATE packet, causing the rpd to crash and restart. Receiving continuous malformed packets results in a sustained DoS condition. This issue predominantly impacts 32-bit Junos OS systems, which can be identified using the 'show version detail' command. Juniper Networks Junos OS versions before 21.4R3-S8, 22.2 before 22.2R3-S4, 22.4 before 22.4R3-S3, 23.2 before 23.2R2-S1, and 23.4 before 23.4R1-S2, as well as Juniper Networks Junos OS Evolved versions before 21.4R3-S8-EVO, 22.2 before 22.2R3-S4-EVO, 22.4 before 22.4R3-S3-EVO, 23.2 before 23.2R2-S1-EVO, and 23.4 before 23.4R1-S2-EVO, and 23.4R2-EVO, are vulnerable to this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share