7.1

CVE-2024-39519

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX7000 Series allows an unauthenticated, adjacent attacker to cause a 

Denial-of-Service (DoS).

On all ACX 7000 Series platforms running 

Junos OS Evolved, and configured with IRBs, if a Customer Edge device (CE) device is dual homed to two Provider Edge devices (PE) a traffic loop will occur when the CE sends multicast packets. This issue can be triggered by IPv4 and IPv6 traffic.


This issue affects Junos OS Evolved: 

All versions from 22.2R1-EVO and later versions before 22.4R2-EVO,

This issue does not affect Junos OS Evolved versions before 22.1R1-EVO.

Data is provided by the National Vulnerability Database (NVD)
JuniperJunos Os Evolved Version >= 22.2 < 22.4
   JuniperAcx7024 Version-
   JuniperAcx7024x Version-
   JuniperAcx7100-32c Version-
   JuniperAcx7100-48l Version-
   JuniperAcx7332 Version-
   JuniperAcx7348 Version-
   JuniperAcx7509 Version-
JuniperJunos Os Evolved Version22.4 Update-
   JuniperAcx7024 Version-
   JuniperAcx7024x Version-
   JuniperAcx7100-32c Version-
   JuniperAcx7100-48l Version-
   JuniperAcx7332 Version-
   JuniperAcx7348 Version-
   JuniperAcx7509 Version-
JuniperJunos Os Evolved Version22.4 Updater1
   JuniperAcx7024 Version-
   JuniperAcx7024x Version-
   JuniperAcx7100-32c Version-
   JuniperAcx7100-48l Version-
   JuniperAcx7332 Version-
   JuniperAcx7348 Version-
   JuniperAcx7509 Version-
JuniperJunos Os Evolved Version22.4 Updater1-s1
   JuniperAcx7024 Version-
   JuniperAcx7024x Version-
   JuniperAcx7100-32c Version-
   JuniperAcx7100-48l Version-
   JuniperAcx7332 Version-
   JuniperAcx7348 Version-
   JuniperAcx7509 Version-
JuniperJunos Os Evolved Version22.4 Updater1-s2
   JuniperAcx7024 Version-
   JuniperAcx7024x Version-
   JuniperAcx7100-32c Version-
   JuniperAcx7100-48l Version-
   JuniperAcx7332 Version-
   JuniperAcx7348 Version-
   JuniperAcx7509 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.24% 0.474
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
sirt@juniper.net 7.1 0 0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
sirt@juniper.net 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-754 Improper Check for Unusual or Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.