CVE-2024-30402Improper Check for Unusual or Exceptional Conditions in Networks Junos OS

Severity
8.2HIGHNVD
EPSS
0.2%
top 61.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12

Description

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When telemetry requests are sent to the device, and the Dynamic Rendering Daemon (drend) is suspended, the l2ald crashes and restarts due to factors outside the attackers control. Repeated occurrences of these events causes a sustained DoS condition.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L

Affected Packages4 packages

CVEListV5juniper_networks/junos_os_evolved21.4-EVO21.4R3-S5-EVO+5
CVEListV5juniper_networks/junos_os20.420.4R3-S10+7
NVDjuniper/junos< 20.4+8

🔴Vulnerability Details

2
CVEList
Junos OS and Junos OS Evolved: The l2ald crashes on receiving telemetry messages from a specific subscription2024-04-12
GHSA
GHSA-8vc5-fgcg-4vh9: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and2024-04-12

📋Vendor Advisories

1
Juniper
CVE-2024-30402: An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and2024-04-12
CVE-2024-30402 — Networks Junos OS vulnerability | cvebase