CVE-2024-21587
published 2024-01-12CVE-2024-21587: An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX…
PriorityP428medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.28%
19.8th percentile
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an attacker directly connected to the vulnerable system who repeatedly flaps DHCP subscriber sessions to cause a slow memory leak, ultimately leading to a Denial of Service (DoS). Memory can only be recovered by manually restarting bbe-smgd.
This issue only occurs if BFD liveness detection for DHCP subscribers is enabled. Systems without BFD liveness detection enabled are not vulnerable to this issue.
Indication of the issue can be observed by periodically executing the 'show system processes extensive' command, which will indicate an increase in memory allocation for bbe-smgd. A small amount of memory is leaked every time a DHCP subscriber logs in, which will become visible over time, ultimately leading to memory starvation.
user@junos> show system processes extensive | match bbe-smgd
13071 root 24 0 415M 201M select 0 0:41 7.28% bbe-smgd{bbe-smgd}
13071 root 20 0 415M 201M select 1 0:04 0.00% bbe-smgd{bbe-smgd}
...
user@junos> show system processes extensive | match bbe-smgd
13071 root 20 0 420M 208M select 0 4:33 0.10% bbe-smgd{bbe-smgd}
13071 root 20 0 420M 208M select 0 0:12 0.00% bbe-smgd{bbe-smgd}
...
This issue affects Juniper Networks Junos OS on MX Series:
* All versions earlier than 20.4R3-S9;
* 21.2 versions earlier than 21.2R3-S7;
* 21.3 versions earlier than 21.3R3-S5;
* 21.4 versions earlier than 21.4R3-S5;
* 22.1 versions earlier than 22.1R3-S4;
* 22.2 versions earlier than 22.2R3-S3;
* 22.3 versions earlier than 22.3R3-S2;
* 22.4 versions earlier than 22.4R2-S2, 22.4R3;
* 23.2 versions earlier than 23.2R1-S1, 23.2R2.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper | mx_series | — | — |
| juniper_networks | junos_os | < 20.4R3-S9 | 20.4R3-S9 |
| juniper_networks | junos_os | >= 21.2 < 21.2R3-S7 | 21.2R3-S7 |
| juniper_networks | junos_os | >= 21.3 < 21.3R3-S5 | 21.3R3-S5 |
| juniper_networks | junos_os | >= 21.4 < 21.4R3-S5 | 21.4R3-S5 |
| juniper_networks | junos_os | >= 22.1 < 22.1R3-S4 | 22.1R3-S4 |
| juniper_networks | junos_os | >= 22.2 < 22.2R3-S3 | 22.2R3-S3 |
| juniper_networks | junos_os | >= 22.3 < 22.3R3-S2 | 22.3R3-S2 |
| juniper_networks | junos_os | >= 22.4 < 22.4R2-S2, 22.4R3 | 22.4R2-S2, 22.4R3 |
| juniper_networks | junos_os | >= 23.2 < 23.2R1-S1, 23.2R2 | 23.2R1-S1, 23.2R2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Juniper
CVE-2024-21587:
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos
vendor_juniper·2024-01-12·CVSS 6.5
CVE-2024-21587 [MEDIUM] CWE-755 CVE-2024-21587:
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos
CVE-2024-21587:
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an attacker directly connected to the vulnerable system who repeatedly flaps DHCP subscriber sessions to cause a slow memory leak, ultimately leading to a Denial of Service (DoS). Memory can only be recovered by manually restarting bbe-smgd.
This issue only occurs if BFD liveness detection for DHCP subscribers is enabled. Systems without BFD liveness detection enabled are not vulnerable to this issue.
Indication of the issue can be observed by periodically executing the 'show system processes extensive' command, which will indicate an increase in memory allocation for bbe-smgd. A small amount of memory
GHSA
GHSA-m2fv-89w7-x6jx: An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos O
ghsa_unreviewed·2024-01-12
CVE-2024-21587 [MEDIUM] CWE-755 GHSA-m2fv-89w7-x6jx: An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos O
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an attacker directly connected to the vulnerable system who repeatedly flaps DHCP subscriber sessions to cause a slow memory leak, ultimately leading to a Denial of Service (DoS). Memory can only be recovered by manually restarting bbe-smgd.
This issue only occurs if BFD liveness detection for DHCP subscribers is enabled. Systems without BFD liveness detection enabled are not vulnerable to this issue.
Indication of the issue can be observed by periodically executing the 'show system processes extensive' command, which will indicate an increase in memory allocation for bbe-smgd. A small amount of memory is leaked every
Suricata
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M2 (CVE-2022-21587)
suricata·2023-01-27·CVSS 9.8
CVE-2022-21587 [CRITICAL] ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M2 (CVE-2022-21587)
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M2 (CVE-2022-21587)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M2 (CVE-2022-21587)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/OA_HTML/BneViewerXMLService"; startswith; fast_pattern; content:"bne:uueupload=TRUE"; reference:url,blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/; reference:cve,2022-21587; classtype:attempted-admin; sid:2044011; rev:2; metadata:attack_target Client_Endpoint, created_at 2023_01_27, cve CVE_2022_21587, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_
Suricata
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M3 (CVE-2022-21587)
suricata·2023-01-27·CVSS 9.8
CVE-2022-21587 [CRITICAL] ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M3 (CVE-2022-21587)
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M3 (CVE-2022-21587)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M3 (CVE-2022-21587)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/OA_HTML/BneDownloadService"; startswith; fast_pattern; content:"bne:uueupload=TRUE"; reference:url,blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/; reference:cve,2022-21587; classtype:attempted-admin; sid:2044012; rev:2; metadata:attack_target Client_Endpoint, created_at 2023_01_27, cve CVE_2022_21587, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_0
Suricata
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M4 (CVE-2022-21587)
suricata·2023-01-27·CVSS 9.8
CVE-2022-21587 [CRITICAL] ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M4 (CVE-2022-21587)
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M4 (CVE-2022-21587)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M4 (CVE-2022-21587)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/OA_HTML/BneOfflineLOVService"; startswith; fast_pattern; content:"bne:uueupload=TRUE"; reference:url,blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/; reference:cve,2022-21587; classtype:attempted-admin; sid:2044013; rev:2; metadata:attack_target Client_Endpoint, created_at 2023_01_27, cve CVE_2022_21587, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024
Suricata
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M1 (CVE-2022-21587)
suricata·2023-01-27·CVSS 9.8
CVE-2022-21587 [CRITICAL] ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M1 (CVE-2022-21587)
ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M1 (CVE-2022-21587)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Oracle E-Business RCE Attempt Inbound M1 (CVE-2022-21587)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/OA_HTML/BneUploaderService"; startswith; fast_pattern; content:"bne:uueupload=TRUE"; reference:url,blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/; reference:cve,2022-21587; classtype:attempted-admin; sid:2044010; rev:2; metadata:attack_target Client_Endpoint, created_at 2023_01_27, cve CVE_2022_21587, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_0
No public exploits indexed.
No writeups or analysis indexed.
2024-01-12
Published