CVE-2024-47505

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 770

Summary

CVE-2024-47505 is a resource exhaustion vulnerability affecting the PFE management daemon (evo-pfemand) in Juniper Networks Junos OS Evolved. An authenticated attacker can trigger a GUID resource leak through specific SNMP GET operations or low-privileged CLI commands, leading to a Denial of Service (DoS) by causing FPCs to hang and requiring manual restart. This issue is identified by increasing Guids values in the 'show platform application-info allocations' command output. Affected versions include all releases before 21.4R3-S7-EVO, 22.1 versions before 22.1R3-S6-EVO, 22.2 versions before 22.2R3-EVO, 22.3 versions before 22.3R3-EVO, and 22.4 versions before 22.4R2-EVO. It is related, but distinct from CVE-2024-47508 and CVE-2024-47509.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share