CVE-2024-47506
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
11/10/2024
Last modified:
15/10/2024
Description
A Deadlock vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).<br />
<br />
When a large amount of traffic is processed by ATP Cloud inspection, a deadlock can occur which will result in a PFE crash and restart. Whether the crash occurs, depends on system internal timing that is outside the attackers control.<br />
<br />
<br />
<br />
This issue affects Junos OS on SRX Series:<br />
<br />
<br />
<br />
* All versions before 21.3R3-S1,<br />
* 21.4 versions before 21.4R3,<br />
* 22.1 versions before 22.1R2,<br />
* 22.2 versions before 22.2R1-S2, 22.2R2.
Impact
Base Score 4.0
8.20
Severity 4.0
HIGH
Base Score 3.x
5.90
Severity 3.x
MEDIUM