CVE-2024-47504
An Improper Validation of Specified Type of Input vulnerability in the packet forwarding engine (pfe) Juniper Networks Junos OS on SRX5000 Series allows an unauthenticated, network based attacker to cause a Denial of Service (Dos).
When a non-clustered SRX5000 device receives a specifically malformed packet this will cause a flowd crash and restart.
This issue affects Junos OS:
Please note that the PR does indicate that earlier versions have been fixed as well, but these won't be adversely impacted by this.
Detalles técnicos trazas, registros y código del informe original
* 22.1 releases 22.1R1 and later before 22.2R3-S5, * 22.3 releases before 22.3R3-S4, * 22.4 releases before 22.4R3-S4, * 23.2 releases before 23.2R2-S2, * 23.4 releases before 23.4R2-S1, * 24.2 releases before 24.2R1-S1, 24.2R2.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X
- Puntuación base: 8.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.62%
- Percentil entre todas las CVEs puntuadas: 48
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1499.004Application or System Exploitationimpact90 %
Vulnerabilidad de validación de entrada en dispositivo SRX5000 accesible por red sin autenticación (AV:N, PR:N, UI:N) que causa DoS del proceso flowd mediante paquete malformado.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-1287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-47504",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-47504",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-10-11T17:19:09.401803Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "sirt@juniper.net",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "sirt@juniper.net",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "AUTOMATIC",
"baseScore": 8.7,
"Automatable": "YES",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "MODERATE",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "sirt@juniper.net",
"affectedData": [
{
"vendor": "Juniper Networks",
"product": "Junos OS",
"versions": [
{
"status": "affected",
"version": "22.2",
"lessThan": "22.2R3-S5",
"versionType": "semver"
},
{
"status": "affected",
"version": "22.3",
"lessThan": "22.3R3-S4",
"versionType": "semver"
},
{
"status": "affected",
"version": "22.4",
"lessThan": "22.4R3-S4",
"versionType": "semver"
},
{
"status": "affected",
"version": "23.2",
"lessThan": "23.2R2-S2",
"versionType": "semver"
},
{
"status": "affected",
"version": "23.4",
"lessThan": "23.4R2-S1",
"versionType": "semver"
},
{
"status": "affected",
"version": "24.2",
"lessThan": "24.2R1-S1, 24.2R2",
"versionType": "semver"
}
],
"platforms": [
"SRX5000 Series"
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*"
],
"vendor": "juniper",
"product": "junos",
"versions": [
{
"status": "affected",
"version": "22.2",
"lessThan": "22.2r3-s5",
"versionType": "semver"
},
{
"status": "affected",
"version": "22.3",
"lessThan": "22.3r3-s4",
"versionType": "semver"
},
{
"status": "affected",
"version": "22.4",
"lessThan": "22.4r3-s4",
"versionType": "semver"
},
{
"status": "affected",
"version": "23.2",
"lessThan": "23.2r2-s2",
"versionType": "semver"
},
{
"status": "affected",
"version": "23.4",
"lessThan": "23.4r2-s1",
"versionType": "semver"
},
{
"status": "affected",
"version": "24.2",
"lessThan": "24.2r1-s1",
"versionType": "semver"
},
{
"status": "affected",
"version": "24.2",
"lessThan": "24.2r2",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-10-11T16:15:11.900",
"references": [
{
"url": "https://supportportal.juniper.net/JSA88134",
"tags": [
"Vendor Advisory"
],
"source": "sirt@juniper.net"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "sirt@juniper.net",
"description": [
{
"lang": "en",
"value": "CWE-1287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An Improper Validation of Specified Type of Input vulnerability in the packet forwarding engine (pfe) Juniper Networks Junos OS on SRX5000 Series allows an unauthenticated, network based attacker to cause a Denial of Service (Dos).\n\nWhen a non-clustered SRX5000 device receives a specifically malformed packet this will cause a flowd crash and restart.\n\nThis issue affects Junos OS:\n\n * 22.1 releases 22.1R1 and later before 22.2R3-S5,\n * 22.3 releases before 22.3R3-S4,\n * 22.4 releases before 22.4R3-S4,\n * 23.2 releases before 23.2R2-S2,\n * 23.4 releases before 23.4R2-S1,\n * 24.2 releases before 24.2R1-S1, 24.2R2.\n\n\nPlease note that the PR does indicate that earlier versions have been fixed as well, but these won't be adversely impacted by this."
},
{
"lang": "es",
"value": "Una vulnerabilidad de validación incorrecta del tipo de entrada especificado en el motor de reenvío de paquetes (pfe) de Juniper Networks Junos OS en la serie SRX5000 permite que un atacante no autenticado basado en la red provoque una denegación de servicio (Dos). Cuando un dispositivo SRX5000 no agrupado recibe un paquete específicamente malformado, esto provocará un bloqueo y reinicio de flowd. Este problema afecta a Junos OS: * 22.1 versiones 22.1R1 y posteriores anteriores a 22.2R3-S5, * 22.3 versiones anteriores a 22.3R3-S4, * 22.4 versiones anteriores a 22.4R3-S4, * 23.2 versiones anteriores a 23.2R2-S2, * 23.4 versiones anteriores a 23.4R2-S1, * 24.2 versiones anteriores a 24.2R1-S1, 24.2R2. Tenga en cuenta que el comunicado de prensa indica que también se han corregido versiones anteriores, pero que estas no se verán afectadas negativamente por esto."
}
],
"lastModified": "2026-06-17T07:57:12.223",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:juniper:junos:22.1:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3F96EBE9-2532-4E35-ABA5-CA68830476A4"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.1:r1-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4D936AE-FD74-4823-A824-2D9F24C25BFB"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.1:r1-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E117E493-F4E1-4568-88E3-F243C74A2662"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.1:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01E3E308-FD9C-4686-8C35-8472A0E99F0D"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.1:r2-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3683A8F5-EE0E-4936-A005-DF7F6B75DED3"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.1:r2-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1B615DBA-8C53-41D4-B264-D3EED8578471"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.1:r3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B3124DD0-9E42-4896-9060-CB7DD07FC342"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.1:r3-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "44F6FD6C-03AF-4D2C-B411-A753DE12A2DA"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.1:r3-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D49FFB60-BA71-4902-9404-E67162919ADC"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.1:r3-s3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EFF72FCA-C440-4D43-9BDB-F712DB413717"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.1:r3-s4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE69E9E3-00FC-41BF-9109-617668CF9A0B"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.3:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CEB98E3F-B0A9-488F-ACFC-56B9485E7C9E"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.3:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "19519212-51DD-4448-B115-8A20A40192CC"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.3:r1-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5CC9909E-AE9F-414D-99B1-83AA04D5297B"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.3:r1-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDE9E767-4713-4EA2-8D00-1382975A4A15"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.3:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59DDA54E-6845-47EB-AE3C-5EC6BD33DFA7"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.3:r2-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "574730B0-56C8-4A03-867B-1737148ED9B1"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.3:r2-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20EBC676-1B26-4A71-8326-0F892124290A"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.3:r3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FB4C0FBF-8813-44E5-B71A-22CBAA603E2F"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.3:r3-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8BCDE58C-80CC-4C5A-9667-8A4468D8D76C"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.3:r3-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "19326769-2F08-4E61-8246-CCE7AE4483F7"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.3:r3-s3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8FB298B9-E0F2-4195-82D4-4EBA879C5CD7"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1379EF30-AF04-4F98-8328-52A631F24737"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.4:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28E42A41-7965-456B-B0AF-9D3229CE4D4C"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.4:r1-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB1A77D6-D3AD-481B-979C-8F778530B175"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.4:r1-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3A064B6B-A99B-4D8D-A62D-B00C7870BC30"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.4:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40813417-A938-4F74-A419-8C5188A35486"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.4:r2-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7FC1BA1A-DF0E-4B15-86BA-24C60E546732"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.4:r2-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EBB967BF-3495-476D-839A-9DBFCBE69F91"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.4:r3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7E5688D6-DCA4-4550-9CD1-A3D792252129"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.4:r3-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8494546C-00EA-49B6-B6FA-FDE42CA5B1FA"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.4:r3-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8BB98579-FA33-4E41-A162-A46E9709FBD3"
},
{
"criteria": "cpe:2.3:o:juniper:junos:22.4:r3-s3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "08E2562F-FB18-4347-8497-7D61B8157EBB"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A78CC80-E8B1-4CDA-BB35-A61833657FA7"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B3B2FE1-C228-46BE-AC76-70C2687050AE"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r1-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F1B16FF0-900F-4AEE-B670-A537139F6909"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r1-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B227E831-30FF-4BE1-B8B2-31829A5610A6"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1ADA814B-EF98-45B1-AF7A-0C89688F7CA5"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r2-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A6FB32DF-D062-4FB9-8777-452978BEC7B7"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "78481ABC-3620-410D-BC78-334657E0BB75"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE8A5BA3-87BD-473A-B229-2AAB2C797005"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r1-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8B74AC3E-8FC9-400A-A176-4F7F21F10756"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r1-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB2D1FCE-8019-4CE1-BA45-D62F91AF7B51"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "175CCB13-76C0-44A4-A71D-41E22B92EB23"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.2:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89524D6D-0B22-4952-AD8E-8072C5A05D5C"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.2:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD69A194-1B03-44EA-8092-79BD10C6F729"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.2:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "266B520A-482A-43F7-90F8-B9D64D30034F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:juniper:srx5400:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2FDDC897-747F-44DD-9599-7266F9B5B7B1"
},
{
"criteria": "cpe:2.3:h:juniper:srx5600:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "68CA098D-CBE4-4E62-9EC0-43E1B6098710"
},
{
"criteria": "cpe:2.3:h:juniper:srx5800:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "66F474D4-79B6-4525-983C-9A9011BD958B"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "sirt@juniper.net"
}