CVE-2024-47508Allocation of Resources Without Limits or Throttling in Networks Junos OS Evolved

Severity
7.1HIGHNVD
EPSS
0.1%
top 67.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11

Description

An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an authenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS).When specific SNMP GET operations or specific low-priviledged CLI commands are executed, a GUID resource leak will occur, eventually leading to exhaustion and resulting in FPCs to hang. Affected FPCs need to be manually restarted to recover.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L

Affected Packages2 packages

CVEListV5juniper_networks/junos_os_evolved21.221.2R3-S8-EVO+3

🔴Vulnerability Details

2
GHSA
GHSA-fc4q-wr43-j7j5: An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved2024-10-11
CVEList
Junos OS Evolved: Specific low privileged CLI commands and SNMP GET requests can trigger a resource leak #22024-10-11

📋Vendor Advisories

1
Juniper
CVE-2024-47508: An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved2024-10-11
CVE-2024-47508 — HIGH severity | cvebase