CVE-2024-21606: Junos OS: SRX Series: When "tcp-encap" is configured and specific packets are received flowd will crash
A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).
In a remote access VPN scenario, if a "tcp-encap-profile" is configured and a sequence of specific packets is received, a flowd crash and restart will be observed.
This issue affects Juniper Networks Junos OS on SRX Series:
All versions earlier than 20.4R3-S8; 21.2 versions earlier than 21.2R3-S6; 21.3 versions earlier than 21.3R3-S5; 21.4 versions earlier than 21.4R3-S5; 22.1 versions earlier than 22.1R3-S3; 22.2 versions earlier than 22.2R3-S3; 22.3 versions earlier than 22.3R3-S1; 22.4 versions earlier than 22.4R2-S2, 22.4R3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 20.4R3-S8 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 21.2R3-S6 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 21.3R3-S5 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 21.4R3-S5 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.1R3-S3 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.2R3-S3 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.3R3-S1 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.4R2-S2 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.4R3 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 23.2R1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21606?
CVE-2024-21606 has a high severity rating, classified as a Denial of Service (DoS) vulnerability.
How do I fix CVE-2024-21606?
To mitigate CVE-2024-21606, upgrade to a patched version of Junos OS that addresses this vulnerability.
Which versions of Junos OS are affected by CVE-2024-21606?
CVE-2024-21606 affects multiple versions of Junos OS, specifically those prior to version 20.4 and specific releases within the 20.4 and 21.x series.
Can CVE-2024-21606 be exploited remotely?
Yes, CVE-2024-21606 can be exploited by network-based, unauthenticated attackers.
What impact does CVE-2024-21606 have on network devices?
The impact of CVE-2024-21606 can result in a Denial of Service (DoS) affecting the availability of network services.