CVE-2024-21604: Junos OS Evolved: A high rate of specific traffic will cause a complete system outage

Published Jan 12, 2024
·
Updated

An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).

If a high rate of specific valid packets are processed by the routing engine (RE) this will lead to a loss of connectivity of the RE with other components of the chassis and thereby a complete and persistent system outage. Please note that a carefully designed lo0 firewall filter will block or limit these packets which should prevent this issue from occurring.

The following log messages can be seen when this issue occurs:

<host> kernel: nfconntrack: nfconntrack: table full, dropping packet This issue affects Juniper Networks Junos OS Evolved:

All versions earlier than 20.4R3-S7-EVO; 21.2R1-EVO and later versions; 21.4-EVO versions earlier than 21.4R3-S5-EVO; 22.1-EVO versions earlier than 22.1R3-S2-EVO; 22.2-EVO versions earlier than 22.2R3-EVO; 22.3-EVO versions earlier than 22.3R2-EVO; 22.4-EVO versions earlier than 22.4R2-EVO.

Affected Software

46 affected components
Juniper Junos OS Evolved=21.2-r1-s1
Juniper Junos OS Evolved=21.2-r1-s2
Juniper Junos OS Evolved=21.2-r2
Juniper Junos OS Evolved=21.2-r2-s1
Juniper Junos OS Evolved=21.2-r2-s2
Juniper Junos OS Evolved=21.2-r3
Juniper Junos OS Evolved=21.2-r3-s1
Juniper Junos OS Evolved=21.2-r3-s2
Juniper Junos OS Evolved=21.2-r3-s3
Juniper Junos OS Evolved=21.2-r3-s4
Juniper Junos OS Evolved=21.2-r3-s5
Juniper Junos OS Evolved=21.2-r3-s6
Juniper Junos OS Evolved=21.4
Juniper Junos OS Evolved=21.4-r1
Juniper Junos OS Evolved=21.4-r1-s1
Juniper Junos OS Evolved=21.4-r1-s2
Juniper Junos OS Evolved=21.4-r2
Juniper Junos OS Evolved=21.4-r2-s1
Juniper Junos OS Evolved=21.4-r2-s2
Juniper Junos OS Evolved=21.4-r3
Juniper Junos OS Evolved=21.4-r3-s1
Juniper Junos OS Evolved=21.4-r3-s2
Juniper Junos OS Evolved=21.4-r3-s3
Juniper Junos OS Evolved=21.4-r3-s4
Juniper Junos OS Evolved=22.1
Juniper Junos OS Evolved=22.1-r1
Juniper Junos OS Evolved=22.1-r1-s1
Juniper Junos OS Evolved=22.1-r1-s2
Juniper Junos OS Evolved=22.1-r2
Juniper Junos OS Evolved=22.1-r2-s1
Juniper Junos OS Evolved=22.1-r3
Juniper Junos OS Evolved=22.1-r3-s1
Juniper Junos OS Evolved=22.2
Juniper Junos OS Evolved=22.2-r1
Juniper Junos OS Evolved=22.2-r1-s1
Juniper Junos OS Evolved=22.2-r2
Juniper Junos OS Evolved=22.2-r2-s1
Juniper Junos OS Evolved=22.2-r2-s2
Juniper Junos OS Evolved=22.3
Juniper Junos OS Evolved=22.3-r1
Juniper Junos OS Evolved=22.3-r1-s1
Juniper Junos OS Evolved=22.3-r1-s2
Juniper Junos OS Evolved=22.4
Juniper Junos OS Evolved=22.4-r1
Juniper Junos OS Evolved=22.4-r1-s1
Juniper Junos OS Evolved=22.4-r1-s2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 20.4R3-S7-EVO
  2. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 21.4R3-S5-EVO
  3. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 22.1R3-S2-EVO
  4. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 22.2R3-EVO
  5. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 22.3R2-EVO
  6. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 22.4R2-EVO
  7. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 23.2R1-EVO
  8. Compensating control

    Implement a carefully designed lo0 firewall filter to block or limit the specific high-rate valid packets that trigger the nf_conntrack table-full condition on the routing engine (RE), to prevent loss of RE connectivity and persistent system outage.

Event History

Jan 12, 2024
CVE Published
via MITRE·12:54 AM
Data Sourced
via MITRE·12:54 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-21604?

CVE-2024-21604 has a severity rating that indicates a high risk of Denial of Service attacks if exploited.

2

How do I fix CVE-2024-21604?

To fix CVE-2024-21604, it is recommended to apply the latest security patches provided by Juniper Networks for affected versions of Junos OS Evolved.

3

Which versions of Junos OS Evolved are affected by CVE-2024-21604?

CVE-2024-21604 affects multiple versions of Junos OS Evolved, including 21.2, 21.4, 22.1, 22.2, 22.3, and 22.4.

4

Who can exploit CVE-2024-21604?

CVE-2024-21604 can be exploited by unauthenticated, network-based attackers.

5

What type of vulnerability is CVE-2024-21604?

CVE-2024-21604 is classified as an Allocation of Resources Without Limits or Throttling vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203