« Volver al listado

CVE-2024-39541

Estado: AnalizadaAlta (7.1)—

An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).

When conflicting information (IP or ISO addresses) about a node is added to the Traffic Engineering (TE) database and then a subsequent operation attempts to process these, rpd will crash and restart.

This issue affects:

Junos OS:

This issue does not affect Junos OS versions earlier than 22.4R1.

Junos OS Evolved:

This issue does not affect Junos OS Evolved versions earlier than

Leer descripción completaMostrar menos

before 22.4R1.

Detalles técnicos trazas, registros y código del informe original
  *  22.4 versions before 22.4R3-S1,
  *  23.2 versions before 23.2R2, 
  *  23.4 versions before 23.4R1-S1, 23.4R2,

  *  22.4-EVO versions before 22.4R3-S2-EVO,
  *  23.2-EVO versions before 23.2R2-EVO,
  *  23.4-EVO versions before 23.4R1-S1-EVO, 23.4R2-EVO,

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-39541",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-39541",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-11T16:55:27.263492Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "sirt@juniper.net",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "sirt@juniper.net",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 7.1,
          "Automatable": "NOT_DEFINED",
          "attackVector": "ADJACENT",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "LOW",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "sirt@juniper.net",
      "affectedData": [
        {
          "vendor": "Juniper Networks",
          "product": "Junos OS",
          "versions": [
            {
              "status": "affected",
              "version": "22.4",
              "lessThan": "22.4R3-S1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "23.2",
              "lessThan": "23.2R2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "23.4",
              "lessThan": "23.4R1-S1, 23.4R2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "22.4R1",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Juniper Networks",
          "product": "Junos OS Evolved",
          "versions": [
            {
              "status": "affected",
              "version": "22.4-EVO",
              "lessThan": "22.4R3-S2-EVO",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "23.2-EVO",
              "lessThan": "23.2R2-EVO",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "23.4-EVO",
              "lessThan": "23.4R1-S1-EVO, 23.4R2-EVO",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "22.4R1",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-07-11T17:15:13.127",
  "references": [
    {
      "url": "https://supportportal.juniper.net/JSA83001",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "sirt@juniper.net"
    },
    {
      "url": "https://supportportal.juniper.net/JSA83001",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "sirt@juniper.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-755"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).\n\nWhen conflicting information (IP or ISO addresses) about a node is added to the Traffic Engineering (TE) database and then a subsequent operation attempts to process these, rpd will crash and restart.\n\nThis issue affects:\n\nJunos OS:\n\n\n\n  *  22.4 versions before 22.4R3-S1,\n  *  23.2 versions before 23.2R2, \n  *  23.4 versions before 23.4R1-S1, 23.4R2, \n\n\n\n\nThis issue does not affect Junos OS versions earlier than 22.4R1.\n\nJunos OS Evolved:\n\n\n\n  *  22.4-EVO versions before 22.4R3-S2-EVO,\n  *  23.2-EVO versions before 23.2R2-EVO,\n  *  23.4-EVO versions before 23.4R1-S1-EVO, 23.4R2-EVO,\n\n\n\n\n\n\nThis issue does not affect Junos OS Evolved versions earlier than \n\nbefore 22.4R1."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de manejo inadecuado de condiciones excepcionales en Routing Protocol Daemon (rpd) de Juniper Networks Junos OS y Junos OS Evolved permite que un atacante adyacente no autenticado provoque una denegación de servicio (DoS). Cuando se agrega información contradictoria (direcciones IP o ISO) sobre un nodo a la base de datos de Ingeniería de tráfico (TE) y luego una operación posterior intenta procesarla, rpd fallará y se reiniciará. Este problema afecta a: Junos OS: * versiones 22.4 anteriores a 22.4R3-S1, * versiones 23.2 anteriores a 23.2R2, * versiones 23.4 anteriores a 23.4R1-S1, 23.4R2. Este problema no afecta a las versiones de Junos OS anteriores a 22.4R1. Junos OS Evolved: * Versiones 22.4-EVO anteriores a 22.4R3-S2-EVO, * Versiones 23.2-EVO anteriores a 23.2R2-EVO, * Versiones 23.4-EVO anteriores a 23.4R1-S1-EVO, 23.4R2-EVO. Este problema no Afecta a las versiones evolucionadas de Junos OS anteriores a la 22.4R1."
    }
  ],
  "lastModified": "2026-06-17T07:42:10.210",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1379EF30-AF04-4F98-8328-52A631F24737"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28E42A41-7965-456B-B0AF-9D3229CE4D4C"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB1A77D6-D3AD-481B-979C-8F778530B175"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:r1-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A064B6B-A99B-4D8D-A62D-B00C7870BC30"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40813417-A938-4F74-A419-8C5188A35486"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:r2-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FC1BA1A-DF0E-4B15-86BA-24C60E546732"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:r2-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EBB967BF-3495-476D-839A-9DBFCBE69F91"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:22.4:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E5688D6-DCA4-4550-9CD1-A3D792252129"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:23.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A78CC80-E8B1-4CDA-BB35-A61833657FA7"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:23.2:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B3B2FE1-C228-46BE-AC76-70C2687050AE"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:23.2:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1B16FF0-900F-4AEE-B670-A537139F6909"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:23.2:r1-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B227E831-30FF-4BE1-B8B2-31829A5610A6"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:23.4:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78481ABC-3620-410D-BC78-334657E0BB75"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:23.4:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE8A5BA3-87BD-473A-B229-2AAB2C797005"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos:23.4:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "175CCB13-76C0-44A4-A71D-41E22B92EB23"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:22.4:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A33C425-921F-4795-B834-608C8F1597E0"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:22.4:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93887799-F62C-4A4A-BCF5-004D0B4D4154"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:22.4:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62C473D2-2612-4480-82D8-8A24D0687BBD"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:22.4:r1-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FB4C5CA-A709-4B13-A9E0-372098A72AD3"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:22.4:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04CE952D-E3C1-4B34-9E65-EC52BFE887AB"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:22.4:r2-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8AE9D1A7-4721-4E1D-B965-FDC38126B1DD"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:22.4:r2-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8643AA3-29EF-48A7-B033-CB60988E214B"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:22.4:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9800BA03-E6BF-4212-B2E7-69C0FD27D294"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:22.4:r3-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ACCA655D-C542-44F1-B183-4C864CFF2D4F"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:23.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6DEAA7FD-385F-4221-907E-65ABC16BE4BE"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:23.2:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DDEC008A-3137-48D1-8ABC-6DB0EFC40E50"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:23.2:r1-s1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "558D234D-BC50-415F-86D6-8E19D6C3ACE0"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:23.2:r1-s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33F4EEEE-77E9-4973-A770-99E7BA2F05F5"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:23.4:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D7F0D73-85EE-4A07-B51B-6BF52ECBA75E"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:23.4:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE777A1F-9CD9-426E-AF1C-FBE01EB9A4A8"
            },
            {
              "criteria": "cpe:2.3:o:juniper:junos_os_evolved:23.4:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB82B22F-9005-4EF0-A1E3-4261757783D4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "sirt@juniper.net"
}