« Volver al listado

CVE-2024-39518

Estado: AnalizadaAlta (8.7)—

A Heap-based Buffer Overflow vulnerability in the telemetry sensor process (sensord) of Juniper Networks Junos OS on MX240, MX480, MX960 platforms using MPC10E causes a steady increase in memory utilization, ultimately leading to a Denial of Service (DoS).

When the device is subscribed to a specific subscription on Junos Telemetry Interface, a slow memory leak occurs and eventually all resources are consumed and the device becomes unresponsive. A manual reboot of the Line Card will be required to restore the device to its normal functioning.

This issue is only seen when telemetry subscription is active.

Leer descripción completaMostrar menos

The Heap memory utilization can be monitored using the following command:   > show system processes extensive

The following command can be used to monitor the memory utilization of the specific sensor   > show system info | match sensord PID NAME MEMORY PEAK MEMORY %CPU THREAD-COUNT CORE-AFFINITY UPTIME

This issue affects Junos OS:

Detalles técnicos trazas, registros y código del informe original
   1986  sensord            877.57MB   877.57MB         2       4           0,2-15          7-21:41:32

  *  from 21.2R3-S5 before 21.2R3-S7, 
  *  from 21.4R3-S4 before 21.4R3-S6, 
  *  from 22.2R3 before 22.2R3-S4, 
  *  from 22.3R2 before 22.3R3-S2, 
  *  from 22.4R1 before 22.4R3, 
  *  from 23.2R1 before 23.2R2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-39518",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-39518",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-11T14:09:55.941009Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "sirt@juniper.net",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "sirt@juniper.net",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.7,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "LOW",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "sirt@juniper.net",
      "affectedData": [
        {
          "vendor": "Juniper Networks",
          "product": "Junos OS",
          "versions": [
            {
              "status": "affected",
              "version": "21.2R3-S5",
              "lessThan": "21.2R3-S7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "21.4R3-S4",
              "lessThan": "21.4R3-S6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "22.2R3",
              "lessThan": "22.2R3-S4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "22.3R2",
              "lessThan": "22.3R3-S2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "22.4R1",
              "lessThan": "22.4R3",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "23.2R1",
              "lessThan": "23.2R2",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "MX240 using MPC10E",
            "MX480 using MPC10E",
            "MX960 using MPC10E"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:juniper:junos_os:*:*:*:*:*:*:*:*"
          ],
          "vendor": "juniper",
          "product": "junos_os",
          "versions": [
            {
              "status": "affected",
              "version": "21.2R3-S5",
              "lessThan": "21.2R3-S7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "21.4R3-S4",
              "lessThan": "21.4R3-S6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "22.2R3",
              "lessThan": "22.2R3-S4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "22.3R2",
              "lessThan": "22.3R3-S2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "22.4R1",
              "lessThan": "22.4R3",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "23.2R1",
              "lessThan": "23.2R2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-07-10T23:15:11.363",
  "references": [
    {
      "url": "https://supportportal.juniper.net/JSA82982",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "sirt@juniper.net"
    },
    {
      "url": "https://supportportal.juniper.net/JSA82982",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "sirt@juniper.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-122"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A Heap-based Buffer Overflow vulnerability in the telemetry sensor process (sensord) of Juniper Networks Junos OS on MX240, MX480, MX960 platforms using MPC10E causes a steady increase in memory utilization, ultimately leading to a Denial of Service (DoS).\n\nWhen the device is subscribed to a specific subscription on Junos Telemetry Interface, a slow memory leak occurs and eventually all resources are consumed and the device becomes unresponsive. A manual reboot of the Line Card will be required to restore the device to its normal functioning. \n\nThis issue is only seen when telemetry subscription is active.\n\nThe Heap memory utilization can be monitored using the following command:\n  > show system processes extensive\n\nThe following command can be used to monitor the memory utilization of the specific sensor\n  > show system info | match sensord\n   PID   NAME                 MEMORY     PEAK MEMORY    %CPU   THREAD-COUNT CORE-AFFINITY   UPTIME\n\n   1986  sensord            877.57MB   877.57MB         2       4           0,2-15          7-21:41:32\n\n\nThis issue affects Junos OS: \n\n\n\n  *  from 21.2R3-S5 before 21.2R3-S7, \n  *  from 21.4R3-S4 before 21.4R3-S6, \n  *  from 22.2R3 before 22.2R3-S4, \n  *  from 22.3R2 before 22.3R3-S2, \n  *  from 22.4R1 before 22.4R3, \n  *  from 23.2R1 before 23.2R2."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de desbordamiento de búfer de almacenamiento dinámico en el proceso del sensor de telemetría (sensord) de Juniper Networks Junos OS en plataformas MX240, MX480, MX960 que utilizan MPC10E provoca un aumento constante en la utilización de la memoria, lo que en última instancia conduce a una denegación de servicio (DoS). Cuando el dispositivo está suscrito a una suscripción específica en Junos Telemetry Interface, se produce una pérdida lenta de memoria y, finalmente, se consumen todos los recursos y el dispositivo deja de responder. Será necesario reiniciar manualmente la tarjeta de línea para restaurar el dispositivo a su funcionamiento normal. Este problema solo se ve cuando la suscripción de telemetría está activa. La utilización de la memoria del montón se puede monitorear usando el siguiente comando: > show system processes extensive El siguiente comando se puede usar para monitorear la utilización de la memoria del sensor específico > show system info | match sensord NOMBRE PID MEMORIA PICO DE MEMORIA %CPU NÚMERO DE HILOS CORE-AFFINITY UPTIME 1986 sensord 877.57MB 877.57MB 2 4 0,2-15 7-21:41:32 Este problema afecta a Junos OS: * de 21.2R3-S5 antes de 21.2 R3-S7, * de 21.4R3-S4 antes de 21.4R3-S6, * de 22.2R3 antes de 22.2R3-S4, * de 22.3R2 antes de 22.3R3-S2, * de 22.4R1 antes de 22.4R3, * de 23.2R1 antes de 23.2 R2."
    }
  ],
  "lastModified": "2026-06-17T07:42:06.160",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:juniper:junos:21.2:r3-s5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2307BF56-640F-49A8-B060-6ACB0F653A61"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:21.2:r3-s6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "737DDF96-7B1D-44E2-AD0F-E2F50858B2A3"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:21.4:r3-s4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B457616-2D91-4913-9A7D-038BBF8F1F66"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:21.4:r3-s5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C470FB4E-A927-4AF3-ACB0-AD1E264218B7"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.2:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "591AA3E6-62A2-4A1A-A04C-E808F71D8B6E"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.2:r3-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "786F993E-32CB-492A-A7CC-A7E4F48EA8B9"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.2:r3-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60CEA89D-BAC4-41CD-A1D1-AA5EDDEBD54A"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.2:r3-s3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC449CC7-B2D6-41CB-8D6C-81DE89E79520"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.3:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59DDA54E-6845-47EB-AE3C-5EC6BD33DFA7"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.3:r2-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "574730B0-56C8-4A03-867B-1737148ED9B1"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.3:r2-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20EBC676-1B26-4A71-8326-0F892124290A"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.3:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB4C0FBF-8813-44E5-B71A-22CBAA603E2F"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.3:r3-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BCDE58C-80CC-4C5A-9667-8A4468D8D76C"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28E42A41-7965-456B-B0AF-9D3229CE4D4C"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB1A77D6-D3AD-481B-979C-8F778530B175"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:r1-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A064B6B-A99B-4D8D-A62D-B00C7870BC30"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40813417-A938-4F74-A419-8C5188A35486"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:r2-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FC1BA1A-DF0E-4B15-86BA-24C60E546732"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:r2-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EBB967BF-3495-476D-839A-9DBFCBE69F91"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:23.2:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B3B2FE1-C228-46BE-AC76-70C2687050AE"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:23.2:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1B16FF0-900F-4AEE-B670-A537139F6909"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:23.2:r1-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B227E831-30FF-4BE1-B8B2-31829A5610A6"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:juniper:mx240:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F4A26704-A6A4-4C4F-9E12-A0A0259491EF"
            },
            {
              "criteria": "cpe:2.3:h:juniper:mx480:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "104858BD-D31D-40E0-8524-2EC311F10EAC"
            },
            {
              "criteria": "cpe:2.3:h:juniper:mx960:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B5E08E1E-0FE4-4294-9497-BBFFECA2A220"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "sirt@juniper.net"
}