CVE-2024-21601: Junos OS: SRX Series: Due to an error in processing TCP events flowd will crash

Published Jan 12, 2024
·
Updated

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the Flow-processing Daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos).

On SRX Series devices when two different threads try to simultaneously process a queue which is used for TCP events flowd will crash. One of these threads can not be triggered externally, so the exploitation of this race condition is outside the attackers direct control.

Continued exploitation of this issue will lead to a sustained DoS.

This issue affects Juniper Networks Junos OS:

21.2 versions earlier than 21.2R3-S5; 21.3 versions earlier than 21.3R3-S5; 21.4 versions earlier than 21.4R3-S4; 22.1 versions earlier than 22.1R3-S3; 22.2 versions earlier than 22.2R3-S1; 22.3 versions earlier than 22.3R2-S2, 22.3R3; 22.4 versions earlier than 22.4R2-S1, 22.4R3.

This issue does not affect Juniper Networks Junos OS versions earlier than 21.2R1.

Affected Software

64 affected components
Juniper Junos=21.2
Juniper Junos=21.2-r1
Juniper Junos=21.2-r1-s1
Juniper Junos=21.2-r1-s2
Juniper Junos=21.2-r2
Juniper Junos=21.2-r2-s1
Juniper Junos=21.2-r2-s2
Juniper Junos=21.2-r3
Juniper Junos=21.2-r3-s1
Juniper Junos=21.2-r3-s2
Juniper Junos=21.2-r3-s3
Juniper Junos=21.2-r3-s4
Juniper Junos=21.3
Juniper Junos=21.3-r1
Juniper Junos=21.3-r1-s1
Juniper Junos=21.3-r1-s2
Juniper Junos=21.3-r2
Juniper Junos=21.3-r2-s1
Juniper Junos=21.3-r2-s2
Juniper Junos=21.3-r3
Juniper Junos=21.3-r3-s1
Juniper Junos=21.3-r3-s2
Juniper Junos=21.3-r3-s3
Juniper Junos=21.3-r3-s4
Juniper Junos=21.4
Juniper Junos=21.4-r1
Juniper Junos=21.4-r1-s1
Juniper Junos=21.4-r1-s2
Juniper Junos=21.4-r2
Juniper Junos=21.4-r2-s1
Juniper Junos=21.4-r2-s2
Juniper Junos=21.4-r3
Juniper Junos=21.4-r3-s1
Juniper Junos=21.4-r3-s2
Juniper Junos=21.4-r3-s3
Juniper Junos=22.1
Juniper Junos=22.1-r1
Juniper Junos=22.1-r1-s1
Juniper Junos=22.1-r1-s2
Juniper Junos=22.1-r2
Juniper Junos=22.1-r2-s1
Juniper Junos=22.1-r2-s2
Juniper Junos=22.1-r3
Juniper Junos=22.1-r3-s1
Juniper Junos=22.1-r3-s2
Juniper Junos=22.2
Juniper Junos=22.2-r1
Juniper Junos=22.2-r1-s1
Juniper Junos=22.2-r1-s2
Juniper Junos=22.2-r2
Juniper Junos=22.2-r2-s1
Juniper Junos=22.2-r2-s2
Juniper Junos=22.2-r3
Juniper Junos=22.3
Juniper Junos=22.3-r1
Juniper Junos=22.3-r1-s1
Juniper Junos=22.3-r1-s2
Juniper Junos=22.3-r2
Juniper Junos=22.3-r2-s1
Juniper Junos=22.4
Juniper Junos=22.4-r1
Juniper Junos=22.4-r1-s1
Juniper Junos=22.4-r1-s2
Juniper Junos=22.4-r2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon) to a version that resolves this vulnerability.

    Fixed in 21.2R3-S5
  2. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon) to a version that resolves this vulnerability.

    Fixed in 21.3R3-S5
  3. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon) to a version that resolves this vulnerability.

    Fixed in 21.4R3-S4
  4. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon) to a version that resolves this vulnerability.

    Fixed in 22.1R3-S3
  5. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon) to a version that resolves this vulnerability.

    Fixed in 22.2R3-S1
  6. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon) to a version that resolves this vulnerability.

    Fixed in 22.3R2-S2
  7. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon) to a version that resolves this vulnerability.

    Fixed in 22.3R3
  8. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon) to a version that resolves this vulnerability.

    Fixed in 22.4R2-S1
  9. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon) to a version that resolves this vulnerability.

    Fixed in 22.4R3
  10. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon) to a version that resolves this vulnerability.

    Fixed in 23.2R1

Event History

Jan 12, 2024
CVE Published
via MITRE·12:53 AM
Data Sourced
via MITRE·12:53 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-21601?

CVE-2024-21601 has a CVSS score that indicates a medium severity vulnerability.

2

How do I fix CVE-2024-21601?

To remediate CVE-2024-21601, upgrade to the patched versions of Junos OS as provided in the security advisory.

3

Who is affected by CVE-2024-21601?

CVE-2024-21601 affects multiple versions of Junos OS on SRX Series devices.

4

What kind of attack vector is used in CVE-2024-21601?

CVE-2024-21601 can be exploited by unauthenticated, network-based attackers.

5

What does CVE-2024-21601 lead to?

CVE-2024-21601 can result in a Denial-of-Service (DoS) condition.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203