CVE-2024-39551
Severity CVSS v4.0:
HIGH
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
11/07/2024
Last modified:
23/01/2026
Description
An Uncontrolled Resource Consumption vulnerability in the H.323 ALG (Application Layer Gateway) of Juniper Networks Junos OS on SRX Series and MX Series with SPC3 and MS-MPC/MIC, allows an unauthenticated network-based attacker to send specific packets causing traffic loss leading to Denial of Service (DoS). <br />
<br />
Continued receipt and processing of these specific packets will sustain the Denial of Service condition.<br />
<br />
The memory usage can be monitored using the below command.<br />
<br />
user@host> show usp memory segment sha data objcache jsf <br />
This issue affects SRX Series and MX Series with SPC3 and MS-MPC/MIC: <br />
<br />
* 20.4 before 20.4R3-S10, <br />
* 21.2 before 21.2R3-S6, <br />
* 21.3 before 21.3R3-S5, <br />
* 21.4 before 21.4R3-S6, <br />
* 22.1 before 22.1R3-S4, <br />
* 22.2 before 22.2R3-S2, <br />
* 22.3 before 22.3R3-S1, <br />
* 22.4 before 22.4R3, <br />
* 23.2 before 23.2R2.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:juniper:junos:20.4:-:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r1-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r2-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r2-s2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r3:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r3-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r3-s2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r3-s3:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r3-s4:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r3-s5:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r3-s6:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r3-s7:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:20.4:r3-s8:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



