8.7

CVE-2024-39540

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on SRX Series, and MX Series with SPC3 allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

When an affected device receives specific valid TCP traffic, the pfe crashes and restarts leading to a momentary but complete service outage.

This issue affects Junos OS:

21.2 releases from 21.2R3-S5 before 21.2R3-S6.

This issue does not affect earlier or later releases.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JuniperJunos Version21.2 Updater3-s5
   JuniperCsrx Version-
   JuniperMx240 Version-
   JuniperMx480 Version-
   JuniperMx960 Version-
   JuniperSrx100 Version-
   JuniperSrx110 Version-
   JuniperSrx1400 Version-
   JuniperSrx1500 Version-
   JuniperSrx1600 Version-
   JuniperSrx210 Version-
   JuniperSrx220 Version-
   JuniperSrx2300 Version-
   JuniperSrx240 Version-
   JuniperSrx240h2 Version-
   JuniperSrx240m Version-
   JuniperSrx300 Version-
   JuniperSrx320 Version-
   JuniperSrx340 Version-
   JuniperSrx3400 Version-
   JuniperSrx345 Version-
   JuniperSrx3600 Version-
   JuniperSrx380 Version-
   JuniperSrx4000 Version-
   JuniperSrx4100 Version-
   JuniperSrx4200 Version-
   JuniperSrx4300 Version-
   JuniperSrx4600 Version-
   JuniperSrx4700 Version-
   JuniperSrx5000 Version-
   JuniperSrx5400 Version-
   JuniperSrx550 Version-
   JuniperSrx550 Hm Version-
   JuniperSrx550m Version-
   JuniperSrx5600 Version-
   JuniperSrx5800 Version-
   JuniperSrx650 Version-
   JuniperVsrx Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.596
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
sirt@juniper.net 8.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
sirt@juniper.net 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-754 Improper Check for Unusual or Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.