CVE-2024-47502

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 770

Summary

CVE-2024-47502 is a resource exhaustion vulnerability affecting the kernel of Juniper Networks Junos OS Evolved. An unauthenticated, network-based attacker can cause a Denial of Service (DoS) by terminating TCP sessions without proper resource management. The affected system fails to clear the state of terminated sessions, leading to a gradual depletion of resources and preventing new in-band control plane connections. This issue is specific to IPv4 and TCP sessions established over interfaces on Field-Programmable Processing Units (FPCs), and does not affect IPv6 or out-of-band connections. Junos OS Evolved versions before 21.4R3-S9-EVO, 22.2 versions before 22.2R3-S4-EVO, 22.4 version before 22.4R3-S3-EVO, 23.2 versions before 23.2R2-S1-EVO, and 23.4 versions before 23.4R2-EVO are known to be affected. To mitigate this vulnerability, affected systems need to have their respective REs restarted manually.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share