CVE-2024-21595: Junos OS: EX4100, EX4400, EX4600, QFX5000 Series: A high rate of specific ICMP traffic will cause the PFE to hang
An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).
If an attacker sends high rate of specific ICMP traffic to a device with VXLAN configured, this causes a deadlock of the PFE and results in the device becoming unresponsive. A manual restart will be required to recover the device.
This issue only affects EX4100, EX4400, EX4600, QFX5000 Series devices.
This issue affects:
Juniper Networks Junos OS
21.4R3 versions earlier than 21.4R3-S4; 22.1R3 versions earlier than 22.1R3-S3; 22.2R2 versions earlier than 22.2R3-S1; 22.3 versions earlier than 22.3R2-S2, 22.3R3; 22.4 versions earlier than 22.4R2; 23.1 versions earlier than 23.1R2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos OS (EX4100, EX4400, EX4600, QFX5000 Series)to a version that resolves this vulnerability.Fixed in 21.4R3-S4 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4100, EX4400, EX4600, QFX5000 Series)to a version that resolves this vulnerability.Fixed in 22.1R3-S3 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4100, EX4400, EX4600, QFX5000 Series)to a version that resolves this vulnerability.Fixed in 22.2R3-S1 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4100, EX4400, EX4600, QFX5000 Series)to a version that resolves this vulnerability.Fixed in 22.3R2-S2 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4100, EX4400, EX4600, QFX5000 Series)to a version that resolves this vulnerability.Fixed in 22.3R3 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4100, EX4400, EX4600, QFX5000 Series)to a version that resolves this vulnerability.Fixed in 22.4R2 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4100, EX4400, EX4600, QFX5000 Series)to a version that resolves this vulnerability.Fixed in 23.1R2 - Upgrade
Upgrade
Juniper Networks Junos OS (EX4100, EX4400, EX4600, QFX5000 Series)to a version that resolves this vulnerability.Fixed in 23.2R1 - Operational
A manual restart will be required to recover the device after applying the updated Junos OS release(s).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21595?
CVE-2024-21595 has been rated with a high severity due to its potential to cause Denial of Service (DoS).
How do I fix CVE-2024-21595?
To mitigate CVE-2024-21595, apply the latest patches provided by Juniper Networks for affected Junos OS versions.
Which Junos OS versions are affected by CVE-2024-21595?
CVE-2024-21595 affects Junos OS versions 21.4-r3, 22.1 (all revisions), 22.2 (all revisions), 22.3 (all revisions), and 22.4 (all revisions).
Can CVE-2024-21595 be exploited remotely?
Yes, CVE-2024-21595 can be exploited remotely by an unauthenticated attacker through high rates of specific ICMP traffic.
What types of devices are impacted by CVE-2024-21595?
CVE-2024-21595 primarily impacts devices running vulnerable Junos OS versions, such as routers and switches from Juniper Networks.