CVE-2024-21603: Junos OS: MX Series: Gathering statistics in a scaled SCU/DCU configuration will lead to a device crash

Published Jan 12, 2024
·
Updated

An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Network Junos OS on MX Series allows a network based attacker with low privileges to cause a denial of service.

If a scaled configuration for Source class usage (SCU) / destination class usage (DCU) (more than 10 route classes) is present and the SCU/DCU statistics are gathered by executing specific SNMP requests or CLI commands, a 'vmcore' for the RE kernel will be seen which leads to a device restart. Continued exploitation of this issue will lead to a sustained DoS.

This issue only affects MX Series devices with MPC10, MPC11 or LC9600, and MX304. No other MX Series devices are affected.

This issue affects Juniper Networks Junos OS:

All versions earlier than 20.4R3-S9; 21.2 versions earlier than 21.2R3-S6; 21.3 versions earlier than 21.3R3-S5; 21.4 versions earlier than 21.4R3; 22.1 versions earlier than 22.1R3; 22.2 versions earlier than 22.2R2; 22.3 versions earlier than 22.3R2.

Affected Software

62 affected components
Juniper Junos=20.4
Juniper Junos=20.4-r1
Juniper Junos=20.4-r1-s1
Juniper Junos=20.4-r2
Juniper Junos=20.4-r2-s1
Juniper Junos=20.4-r2-s2
Juniper Junos=20.4-r3
Juniper Junos=20.4-r3-s1
Juniper Junos=20.4-r3-s2
Juniper Junos=20.4-r3-s3
Juniper Junos=20.4-r3-s4
Juniper Junos=20.4-r3-s5
Juniper Junos=20.4-r3-s6
Juniper Junos=20.4-r3-s7
Juniper Junos=20.4-r3-s8
Juniper Junos=21.2
Juniper Junos=21.2-r1
Juniper Junos=21.2-r1-s1
Juniper Junos=21.2-r1-s2
Juniper Junos=21.2-r2
Juniper Junos=21.2-r2-s1
Juniper Junos=21.2-r2-s2
Juniper Junos=21.2-r3
Juniper Junos=21.2-r3-s1
Juniper Junos=21.2-r3-s2
Juniper Junos=21.2-r3-s3
Juniper Junos=21.2-r3-s4
Juniper Junos=21.2-r3-s5
Juniper Junos=21.3
Juniper Junos=21.3-r1
Juniper Junos=21.3-r1-s1
Juniper Junos=21.3-r1-s2
Juniper Junos=21.3-r2
Juniper Junos=21.3-r2-s1
Juniper Junos=21.3-r2-s2
Juniper Junos=21.3-r3
Juniper Junos=21.3-r3-s1
Juniper Junos=21.3-r3-s2
Juniper Junos=21.3-r3-s3
Juniper Junos=21.3-r3-s4
Juniper Junos=21.4
Juniper Junos=21.4-r1
Juniper Junos=21.4-r1-s1
Juniper Junos=21.4-r1-s2
Juniper Junos=21.4-r2
Juniper Junos=21.4-r2-s1
Juniper Junos=21.4-r2-s2
Juniper Junos=22.1
Juniper Junos=22.1-r1
Juniper Junos=22.1-r1-s1
Juniper Junos=22.1-r1-s2
Juniper Junos=22.1-r2
Juniper Junos=22.1-r2-s1
Juniper Junos=22.1-r2-s2
Juniper Junos=22.2
Juniper Junos=22.2-r1
Juniper Junos=22.2-r1-s1
Juniper Junos=22.2-r1-s2
Juniper Junos=22.3
Juniper Junos=22.3-r1
Juniper Junos=22.3-r1-s1
Juniper Junos=22.3-r1-s2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Juniper Network Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 20.4R3-S9
  2. Upgrade

    Upgrade Juniper Network Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 21.2R3-S6
  3. Upgrade

    Upgrade Juniper Network Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 21.3R3-S5
  4. Upgrade

    Upgrade Juniper Network Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 21.4R3
  5. Upgrade

    Upgrade Juniper Network Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 22.1R3
  6. Upgrade

    Upgrade Juniper Network Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 22.2R2
  7. Upgrade

    Upgrade Juniper Network Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 22.3R2
  8. Upgrade

    Upgrade Juniper Network Junos OS (MX Series) to a version that resolves this vulnerability.

    Fixed in 22.4R1

Event History

Jan 12, 2024
CVE Published
via MITRE·12:54 AM
Data Sourced
via MITRE·12:54 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-21603?

CVE-2024-21603 has a medium severity level, as it allows a network-based attacker to cause a denial of service with low privileges.

2

How do I fix CVE-2024-21603?

To fix CVE-2024-21603, apply the latest patches or updates provided by Juniper Networks for the affected versions of Junos OS.

3

Which versions of Junos OS are affected by CVE-2024-21603?

CVE-2024-21603 affects Junos OS versions 20.4 and 21.2 through 22.3, including specific release iterations.

4

What type of attack does CVE-2024-21603 enable?

CVE-2024-21603 enables a denial of service attack that can be executed by a low-privileged network-based attacker.

5

Is authentication required for exploiting CVE-2024-21603?

Authentication is not required to exploit CVE-2024-21603 since it can be executed by low-privileged attackers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203