CVE-2024-30402 — Improper Check for Unusual or Exceptional Conditions in Networks Junos OS
Severity
8.2HIGHNVD
EPSS
0.2%
top 61.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).
When telemetry requests are sent to the device, and the Dynamic Rendering Daemon (drend) is suspended, the l2ald crashes and restarts due to factors outside the attackers control. Repeated occurrences of these events causes a sustained DoS condition.
…
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
Affected Packages4 packages
🔴Vulnerability Details
2CVEList▶
Junos OS and Junos OS Evolved: The l2ald crashes on receiving telemetry messages from a specific subscription↗2024-04-12
GHSA▶
GHSA-8vc5-fgcg-4vh9: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and↗2024-04-12
📋Vendor Advisories
1Juniper▶
CVE-2024-30402: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and↗2024-04-12