cbcvebase.
CVE-2024-47507
published 2024-10-11

CVE-2024-47507: An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved…

medium6.9CVSS 4.0
AVNACLATNPRNUINVCNVILVANSCNSILSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREMUX
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an integrity impact to the downstream devices. When a peer sends a BGP update message which contains the aggregator attribute with an ASN value of zero (0), rpd accepts and propagates this attribute, which can cause issues for downstream BGP peers receiving this. This issue affects: Junos OS: * All versions before 21.4R3-S6, * 22.2 versions before 22.2R3-S3, * 22.4 versions before 22.4R3; Junos OS Evolved: * All versions before 21.4R3-S7-EVO, * 22.2 versions before 22.2R3-S4-EVO, * 22.4 versions before 22.4R3-EVO.

Affected

15 ranges
VendorProductVersion rangeFixed in
juniperjunos< 21.421.4
juniperjunos
juniperjunos
juniperjunos
juniperjunos_os
juniperjunos_os_evolved< 21.421.4
juniperjunos_os_evolved
juniperjunos_os_evolved
juniperjunos_os_evolved
juniper_networksjunos_os< 21.4R3-S621.4R3-S6
juniper_networksjunos_os>= 22.2 < 22.2R3-S322.2R3-S3
juniper_networksjunos_os>= 22.4 < 22.4R322.4R3
juniper_networksjunos_os_evolved< 21.4R3-S7-EVO21.4R3-S7-EVO
juniper_networksjunos_os_evolved>= 22.2 < 22.2R3-S4-EVO22.2R3-S4-EVO
juniper_networksjunos_os_evolved>= 22.4 < 22.4R3-EVO22.4R3-EVO