CVE-2024-21601: Junos OS: SRX Series: Due to an error in processing TCP events flowd will crash
A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the Flow-processing Daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos).
On SRX Series devices when two different threads try to simultaneously process a queue which is used for TCP events flowd will crash. One of these threads can not be triggered externally, so the exploitation of this race condition is outside the attackers direct control.
Continued exploitation of this issue will lead to a sustained DoS.
This issue affects Juniper Networks Junos OS:
21.2 versions earlier than 21.2R3-S5; 21.3 versions earlier than 21.3R3-S5; 21.4 versions earlier than 21.4R3-S4; 22.1 versions earlier than 22.1R3-S3; 22.2 versions earlier than 22.2R3-S1; 22.3 versions earlier than 22.3R2-S2, 22.3R3; 22.4 versions earlier than 22.4R2-S1, 22.4R3.
This issue does not affect Juniper Networks Junos OS versions earlier than 21.2R1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon)to a version that resolves this vulnerability.Fixed in 21.2R3-S5 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon)to a version that resolves this vulnerability.Fixed in 21.3R3-S5 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon)to a version that resolves this vulnerability.Fixed in 21.4R3-S4 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon)to a version that resolves this vulnerability.Fixed in 22.1R3-S3 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon)to a version that resolves this vulnerability.Fixed in 22.2R3-S1 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon)to a version that resolves this vulnerability.Fixed in 22.3R2-S2 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon)to a version that resolves this vulnerability.Fixed in 22.3R3 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon)to a version that resolves this vulnerability.Fixed in 22.4R2-S1 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon)to a version that resolves this vulnerability.Fixed in 22.4R3 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series) - flowd (Flow-processing Daemon)to a version that resolves this vulnerability.Fixed in 23.2R1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21601?
CVE-2024-21601 has a CVSS score that indicates a medium severity vulnerability.
How do I fix CVE-2024-21601?
To remediate CVE-2024-21601, upgrade to the patched versions of Junos OS as provided in the security advisory.
Who is affected by CVE-2024-21601?
CVE-2024-21601 affects multiple versions of Junos OS on SRX Series devices.
What kind of attack vector is used in CVE-2024-21601?
CVE-2024-21601 can be exploited by unauthenticated, network-based attackers.
What does CVE-2024-21601 lead to?
CVE-2024-21601 can result in a Denial-of-Service (DoS) condition.