7.1

CVE-2024-47493

A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of the Juniper Networks Junos OS on the MX Series platforms with Trio-based FPCs allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).

In case of channelized Modular Interface Cards (MICs), every physical interface flap operation will leak heap memory. Over a period of time, continuous physical interface flap operations causes local FPC  to eventually run out of memory and crash.  

Below CLI command can be used to check the memory usage over a period of time:

  user@host> show chassis fpc























                Temp  CPU Utilization (%)   CPU Utilization (%)  Memory   
Utilization (%)
  Slot State      (C)  Total  Interrupt      1min   5min  
15min DRAM (MB) Heap     Buffer

  0 
Online       43     41         
2                           2048       49         14

  1 
Online       43     41         
2                          
2048       49         14

  2 
Online       43     41         
2                          
2048       49         14









This issue affects Junos OS on MX Series: 




  *  All versions before 21.2R3-S7, 
  *  from 21.4 before 21.4R3-S6, 
  *  from 22.1 before 22.1R3-S5, 
  *  from 22.2 before 22.2R3-S3, 
  *  from 22.3 before 22.3R3-S2, 
  *  from 22.4 before 22.4R3, 
  *  from 23.2 before 23.2R2, 
  *  from 23.4 before 23.4R2.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerJuniper Networks
Produkt Junos OS
Default Statusunaffected
Version < 21.2R3-S7
Version 0
Status affected
Version < 21.4R3-S6
Version 21.4
Status affected
Version < 22.1R3-S5
Version 22.1
Status affected
Version < 22.2R3-S3
Version 22.2
Status affected
Version < 22.3R3-S2
Version 22.3
Status affected
Version < 22.4R3
Version 22.4
Status affected
Version < 23.2R2
Version 23.2
Status affected
Version < 23.4R2
Version 23.4
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.196
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
sirt@juniper.net 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
sirt@juniper.net 7.1 0 0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:X/U:Green
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.