7.1
CVE-2024-30386
- EPSS 0.08%
- Veröffentlicht 12.04.2024 16:15:37
- Zuletzt bearbeitet 06.02.2025 20:36:32
- Quelle sirt@juniper.net
- Teams Watchlist Login
- Unerledigt Login
A Use-After-Free vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause l2ald to crash leading to a Denial-of-Service (DoS). In an EVPN-VXLAN scenario, when state updates are received and processed by the affected system, the correct order of some processing steps is not ensured, which can lead to an l2ald crash and restart. Whether the crash occurs depends on system internal timing which is outside the attackers control. This issue affects: Junos OS: * All versions before 20.4R3-S8, * 21.2 versions before 21.2R3-S6, * 21.3 versions before 21.3R3-S5, * 21.4 versions before 21.4R3-S4, * 22.1 versions before 22.1R3-S3, * 22.2 versions before 22.2R3-S1, * 22.3 versions before 22.3R3,, * 22.4 versions before 22.4R2; Junos OS Evolved: * All versions before 20.4R3-S8-EVO, * 21.2-EVO versions before 21.2R3-S6-EVO, * 21.3-EVO versions before 21.3R3-S5-EVO, * 21.4-EVO versions before 21.4R3-S4-EVO, * 22.1-EVO versions before 22.1R3-S3-EVO, * 22.2-EVO versions before 22.2R3-S1-EVO, * 22.3-EVO versions before 22.3R3-EVO, * 22.4-EVO versions before 22.4R2-EVO.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juniper ≫ Junos Os Evolved Version < 20.4
Juniper ≫ Junos Os Evolved Version20.4 Update-
Juniper ≫ Junos Os Evolved Version20.4 Updater1
Juniper ≫ Junos Os Evolved Version20.4 Updater1-s1
Juniper ≫ Junos Os Evolved Version20.4 Updater1-s2
Juniper ≫ Junos Os Evolved Version20.4 Updater2
Juniper ≫ Junos Os Evolved Version20.4 Updater2-s1
Juniper ≫ Junos Os Evolved Version20.4 Updater2-s2
Juniper ≫ Junos Os Evolved Version20.4 Updater2-s3
Juniper ≫ Junos Os Evolved Version20.4 Updater3
Juniper ≫ Junos Os Evolved Version20.4 Updater3-s1
Juniper ≫ Junos Os Evolved Version20.4 Updater3-s2
Juniper ≫ Junos Os Evolved Version20.4 Updater3-s3
Juniper ≫ Junos Os Evolved Version20.4 Updater3-s4
Juniper ≫ Junos Os Evolved Version20.4 Updater3-s5
Juniper ≫ Junos Os Evolved Version20.4 Updater3-s6
Juniper ≫ Junos Os Evolved Version20.4 Updater3-s7
Juniper ≫ Junos Os Evolved Version21.2 Update-
Juniper ≫ Junos Os Evolved Version21.2 Updater1
Juniper ≫ Junos Os Evolved Version21.2 Updater1-s1
Juniper ≫ Junos Os Evolved Version21.2 Updater1-s2
Juniper ≫ Junos Os Evolved Version21.2 Updater2
Juniper ≫ Junos Os Evolved Version21.2 Updater2-s1
Juniper ≫ Junos Os Evolved Version21.2 Updater2-s2
Juniper ≫ Junos Os Evolved Version21.2 Updater3
Juniper ≫ Junos Os Evolved Version21.2 Updater3-s1
Juniper ≫ Junos Os Evolved Version21.2 Updater3-s2
Juniper ≫ Junos Os Evolved Version21.2 Updater3-s3
Juniper ≫ Junos Os Evolved Version21.2 Updater3-s4
Juniper ≫ Junos Os Evolved Version21.2 Updater3-s5
Juniper ≫ Junos Os Evolved Version21.3 Update-
Juniper ≫ Junos Os Evolved Version21.3 Updater1
Juniper ≫ Junos Os Evolved Version21.3 Updater1-s1
Juniper ≫ Junos Os Evolved Version21.3 Updater2
Juniper ≫ Junos Os Evolved Version21.3 Updater2-s1
Juniper ≫ Junos Os Evolved Version21.3 Updater2-s2
Juniper ≫ Junos Os Evolved Version21.3 Updater3
Juniper ≫ Junos Os Evolved Version21.3 Updater3-s1
Juniper ≫ Junos Os Evolved Version21.3 Updater3-s2
Juniper ≫ Junos Os Evolved Version21.3 Updater3-s3
Juniper ≫ Junos Os Evolved Version21.3 Updater3-s4
Juniper ≫ Junos Os Evolved Version21.4 Update-
Juniper ≫ Junos Os Evolved Version21.4 Updater1
Juniper ≫ Junos Os Evolved Version21.4 Updater1-s1
Juniper ≫ Junos Os Evolved Version21.4 Updater1-s2
Juniper ≫ Junos Os Evolved Version21.4 Updater2
Juniper ≫ Junos Os Evolved Version21.4 Updater2-s1
Juniper ≫ Junos Os Evolved Version21.4 Updater2-s2
Juniper ≫ Junos Os Evolved Version21.4 Updater3
Juniper ≫ Junos Os Evolved Version21.4 Updater3-s1
Juniper ≫ Junos Os Evolved Version21.4 Updater3-s2
Juniper ≫ Junos Os Evolved Version21.4 Updater3-s3
Juniper ≫ Junos Os Evolved Version22.1 Update-
Juniper ≫ Junos Os Evolved Version22.1 Updater1
Juniper ≫ Junos Os Evolved Version22.1 Updater1-s1
Juniper ≫ Junos Os Evolved Version22.1 Updater1-s2
Juniper ≫ Junos Os Evolved Version22.1 Updater2
Juniper ≫ Junos Os Evolved Version22.1 Updater2-s1
Juniper ≫ Junos Os Evolved Version22.1 Updater3
Juniper ≫ Junos Os Evolved Version22.1 Updater3-s1
Juniper ≫ Junos Os Evolved Version22.1 Updater3-s2
Juniper ≫ Junos Os Evolved Version22.2 Update-
Juniper ≫ Junos Os Evolved Version22.2 Updater1
Juniper ≫ Junos Os Evolved Version22.2 Updater1-s1
Juniper ≫ Junos Os Evolved Version22.2 Updater1-s2
Juniper ≫ Junos Os Evolved Version22.2 Updater2
Juniper ≫ Junos Os Evolved Version22.2 Updater2-s1
Juniper ≫ Junos Os Evolved Version22.2 Updater2-s2
Juniper ≫ Junos Os Evolved Version22.2 Updater3
Juniper ≫ Junos Os Evolved Version22.3 Update-
Juniper ≫ Junos Os Evolved Version22.3 Updater1
Juniper ≫ Junos Os Evolved Version22.3 Updater1-s1
Juniper ≫ Junos Os Evolved Version22.3 Updater1-s2
Juniper ≫ Junos Os Evolved Version22.3 Updater2
Juniper ≫ Junos Os Evolved Version22.3 Updater2-s1
Juniper ≫ Junos Os Evolved Version22.3 Updater2-s2
Juniper ≫ Junos Os Evolved Version22.4 Update-
Juniper ≫ Junos Os Evolved Version22.4 Updater1
Juniper ≫ Junos Os Evolved Version22.4 Updater1-s1
Juniper ≫ Junos Os Evolved Version22.4 Updater1-s2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.08% | 0.239 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
sirt@juniper.net | 7.1 | 0 | 0 |
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
sirt@juniper.net | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.