7.5

CVE-2024-21595

Junos OS: EX4100, EX4400, EX4600, QFX5000 Series: A high rate of specific ICMP traffic will cause the PFE to hang

An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).

If an attacker sends high rate of specific ICMP traffic to a device with VXLAN configured, this causes a deadlock of the PFE and results in the device becoming unresponsive. A manual restart will be required to recover the device.

This issue only affects EX4100, EX4400, EX4600, QFX5000 Series devices.

This issue affects:

Juniper Networks Junos OS



  *  21.4R3 versions earlier than 21.4R3-S4;
  *  22.1R3 versions earlier than 22.1R3-S3;
  *  22.2R2 versions earlier than 22.2R3-S1;
  *  22.3 versions earlier than 22.3R2-S2, 22.3R3;
  *  22.4 versions earlier than 22.4R2;
  *  23.1 versions earlier than 23.1R2.






Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JuniperJunos Version21.4 Updater3
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version21.4 Updater3-s1
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version21.4 Updater3-s2
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version21.4 Updater3-s3
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.1 Updater3
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.1 Updater3-s1
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.1 Updater3-s2
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.2 Updater2
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.2 Updater2-s1
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.2 Updater2-s2
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.2 Updater3
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.3 Update-
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.3 Updater1
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.3 Updater1-s1
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.3 Updater1-s2
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.3 Updater2
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.3 Updater2-s1
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.4 Update-
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.4 Updater1
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.4 Updater1-s1
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version22.4 Updater1-s2
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
JuniperJunos Version23.1 Updater1
   JuniperEx4100 Version-
   JuniperEx4400 Version-
   JuniperEx4600 Version-
   JuniperQfx5100 Version-
   JuniperQfx5100-96s Version-
   JuniperQfx5110 Version-
   JuniperQfx5120 Version-
   JuniperQfx5130 Version-
   JuniperQfx5200 Version-
   JuniperQfx5200-32c Version-
   JuniperQfx5200-48y Version-
   JuniperQfx5210 Version-
   JuniperQfx5210-64c Version-
   JuniperQfx5220 Version-
   JuniperQfx5700 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.304
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
sirt@juniper.net 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-1286 Improper Validation of Syntactic Correctness of Input

The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.