CVE-2024-47494

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 367

Summary

CVE-2024-47494 is a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Juniper Networks' Junos OS and the AgentD process. An attacker who has already caused impact on established sessions can manipulate counter changes, leading AgentD to attempt reaping a sensor that has already been destroyed. This memory corruption results in a Denial of Service (DoS) crash of the Field-Programmable Circuit (FPC). Affected versions of Junos OS include all versions before 21.4R3-S9, as well as certain versions from 22.2, 22.3, 22.4, 23.2, and 23.4. The FPC recovers automatically without user intervention after the crash, but the vulnerability poses a significant risk for DoS attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share