CVE-2024-47496

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 476

Summary

CVE-2024-47496 is a NULL Pointer Dereference vulnerability impacting the Packet Forwarding Engine (pfe) in Juniper Networks Junos OS. This flaw enables local, low-privileged attackers to trigger a Denial-of-Service (DoS) condition on MX Series devices with Line cards MPC1-MPC9. The pfe crashes when a specific command is executed, interrupting traffic forwarding until the system recovers. This issue affects Junos OS on various versions, including all versions before 21.4R3-S9, from 22.2 before 22.2R3-S5, from 22.3 before 22.3R3-S4, from 22.4 before 22.4R3-S2, and from 23.2 before 23.2R2-S1. Repeated command execution creates a sustained DoS condition.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Juniper Junos

Affected Vendors

  • Juniper Networks