CVE-2024-39535
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
11/07/2024
Last modified:
22/01/2026
Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).<br />
<br />
When a device has a Layer 3 or an IRB interface configured in a VPLS instance and specific traffic is received, the evo-pfemand processes crashes which causes a service outage for the respective FPC until the system is recovered manually.<br />
<br />
This issue only affects Junos OS Evolved 22.4R2-S1 and 22.4R2-S2 releases and is fixed in 22.4R3. No other releases are affected.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:juniper:junos_os_evolved:22.4:r2-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos_os_evolved:22.4:r2-s2:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:acx7020:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:acx7024:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:acx7024x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:acx7100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:acx7300:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:juniper:acx7509:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



