CVE-2024-39551

Severity CVSS v4.0:
HIGH
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
11/07/2024
Last modified:
23/01/2026

Description

An Uncontrolled Resource Consumption vulnerability in the H.323 ALG (Application Layer Gateway) of  Juniper Networks Junos OS on SRX Series and MX Series with SPC3 and MS-MPC/MIC, allows an unauthenticated network-based attacker to send specific packets causing traffic loss leading to Denial of Service (DoS). <br /> <br /> Continued receipt and processing of these specific packets will sustain the Denial of Service condition.<br /> <br /> The memory usage can be monitored using the below command.<br /> <br />   user@host&gt; show usp memory segment sha data objcache jsf <br /> This issue affects SRX Series and MX Series with SPC3 and MS-MPC/MIC: <br /> <br /> *  20.4 before 20.4R3-S10, <br /> *  21.2 before 21.2R3-S6, <br /> *  21.3 before 21.3R3-S5, <br /> *  21.4 before 21.4R3-S6, <br /> *  22.1 before 22.1R3-S4, <br /> *  22.2 before 22.2R3-S2, <br /> *  22.3 before 22.3R3-S1, <br /> *  22.4 before 22.4R3, <br /> *  23.2 before 23.2R2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:juniper:junos:20.4:-:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r1-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r2-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r2-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r3:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r3-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r3-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r3-s3:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r3-s4:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r3-s5:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r3-s6:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r3-s7:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:20.4:r3-s8:*:*:*:*:*:*