CVE-2024-30387Missing Synchronization in Networks Junos OS

Severity
7.1HIGHNVD
EPSS
0.1%
top 79.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12

Description

A Missing Synchronization vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on ACX5448 and ACX710 allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). If an interface flaps while the system gathers statistics on that interface, two processes simultaneously access a shared resource which leads to a PFE crash and restart. This issue affects Junos OS: * All versions before 20.4R3-S9, * 21.2 versions before 21.2R3-S5, * 21.3 versions bef

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L

Affected Packages2 packages

CVEListV5juniper_networks/junos_os21.221.2R3-S5+7
NVDjuniper/junos< 20.4+8

🔴Vulnerability Details

2
CVEList
Junos OS: ACX5448 & ACX710: Due to interface flaps the PFE process can crash2024-04-12
GHSA
GHSA-h843-jc82-h6jf: A Missing Synchronization vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on ACX5448 and ACX710 allows an unauthentic2024-04-12

📋Vendor Advisories

1
Juniper
CVE-2024-30387: A Missing Synchronization vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on ACX5448 and ACX710 allows an unauthentic2024-04-12
CVE-2024-30387 — Missing Synchronization | cvebase