CVE-2024-21602: Junos OS Evolved: ACX7024, ACX7100-32C and ACX7100-48L: Traffic stops when a specific IPv4 UDP packet is received by the RE
A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS Evolved on ACX7024, ACX7100-32C and ACX7100-48L allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).
If a specific IPv4 UDP packet is received and sent to the Routing Engine (RE) packetio crashes and restarts which causes a momentary traffic interruption. Continued receipt of such packets will lead to a sustained DoS.
This issue does not happen with IPv6 packets.
This issue affects Juniper Networks Junos OS Evolved on ACX7024, ACX7100-32C and ACX7100-48L:
21.4-EVO versions earlier than 21.4R3-S6-EVO; 22.1-EVO versions earlier than 22.1R3-S5-EVO; 22.2-EVO versions earlier than 22.2R2-S1-EVO, 22.2R3-EVO; 22.3-EVO versions earlier than 22.3R2-EVO.
This issue does not affect Juniper Networks Junos OS Evolved versions earlier than 21.4R1-EVO.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 21.4R3-S6-EVO - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 22.1R3-S5-EVO - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 22.2R2-S1-EVO - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 22.2R3-EVO - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 22.3R2-EVO - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 22.4R1-EVO - Compensating control
Until upgraded, prevent the specific IPv4 UDP packet from reaching the device Routing Engine (RE); note that the issue does not occur with IPv6 packets.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21602?
CVE-2024-21602 has a high severity rating due to its potential to cause a Denial of Service (DoS).
How do I fix CVE-2024-21602?
To mitigate CVE-2024-21602, it's recommended to upgrade to a patched version of Junos OS Evolved that addresses the vulnerability.
What devices are affected by CVE-2024-21602?
CVE-2024-21602 affects Juniper Networks Junos OS Evolved on the ACX7024, ACX7100-32C, and ACX7100-48L platforms.
What type of attack does CVE-2024-21602 facilitate?
CVE-2024-21602 allows an unauthenticated, network-based attacker to exploit a NULL Pointer Dereference vulnerability, resulting in a Denial of Service.
Is CVE-2024-21602 exploitable remotely?
Yes, CVE-2024-21602 is vulnerable to remote exploitation as it can be triggered by specific IPv4 UDP packets sent to the Routing Engine.