CVE-2024-47502
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-47502 is a resource exhaustion vulnerability affecting the kernel of Juniper Networks Junos OS Evolved. An unauthenticated, network-based attacker can cause a Denial of Service (DoS) by terminating TCP sessions without proper resource management. The affected system fails to clear the state of terminated sessions, leading to a gradual depletion of resources and preventing new in-band control plane connections. This issue is specific to IPv4 and TCP sessions established over interfaces on Field-Programmable Processing Units (FPCs), and does not affect IPv6 or out-of-band connections. Junos OS Evolved versions before 21.4R3-S9-EVO, 22.2 versions before 22.2R3-S4-EVO, 22.4 version before 22.4R3-S3-EVO, 23.2 versions before 23.2R2-S1-EVO, and 23.4 versions before 23.4R2-EVO are known to be affected. To mitigate this vulnerability, affected systems need to have their respective REs restarted manually.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.