CVE-2024-21616: Junos OS: MX Series and SRX Series: Processing of a specific SIP packet causes NAT IP allocation to fail

Published Jan 12, 2024
·
Updated

An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).

On all Junos OS MX Series and SRX Series platforms, when SIP ALG is enabled, and a specific SIP packet is received and processed, NAT IP allocation fails for genuine traffic, which causes Denial of Service (DoS). Continuous receipt of this specific SIP ALG packet will cause a sustained DoS condition.

NAT IP usage can be monitored by running the following command.

user@srx> show security nat resource-usage source-pool <sourcepoolname>

Pool name: sourcepoolname .. Address Factor-index Port-range Used Avail Total Usage X.X.X.X 0 Single Ports 50258 52342 62464 96% <<<<< - Alg Ports 0 2048 2048 0% This issue affects:

Juniper Networks Junos OS on MX Series and SRX Series

All versions earlier than 21.2R3-S6; 21.3 versions earlier than 21.3R3-S5; 21.4 versions earlier than 21.4R3-S5; 22.1 versions earlier than 22.1R3-S4; 22.2 versions earlier than 22.2R3-S3; 22.3 versions earlier than 22.3R3-S1; 22.4 versions earlier than 22.4R2-S2, 22.4R3; 23.2 versions earlier than 23.2R1-S1, 23.2R2.

Affected Software

74 affected components
Juniper Junos=21.2
Juniper Junos=21.2-r1
Juniper Junos=21.2-r1-s1
Juniper Junos=21.2-r1-s2
Juniper Junos=21.2-r2
Juniper Junos=21.2-r2-s1
Juniper Junos=21.2-r2-s2
Juniper Junos=21.2-r3
Juniper Junos=21.2-r3-s1
Juniper Junos=21.2-r3-s2
Juniper Junos=21.2-r3-s3
Juniper Junos=21.2-r3-s4
Juniper Junos=21.2-r3-s5
Juniper Junos=21.3
Juniper Junos=21.3-r1
Juniper Junos=21.3-r1-s1
Juniper Junos=21.3-r1-s2
Juniper Junos=21.3-r2
Juniper Junos=21.3-r2-s1
Juniper Junos=21.3-r2-s2
Juniper Junos=21.3-r3
Juniper Junos=21.3-r3-s1
Juniper Junos=21.3-r3-s2
Juniper Junos=21.3-r3-s3
Juniper Junos=21.3-r3-s4
Juniper Junos=21.4
Juniper Junos=21.4-r1
Juniper Junos=21.4-r1-s1
Juniper Junos=21.4-r1-s2
Juniper Junos=21.4-r2
Juniper Junos=21.4-r2-s1
Juniper Junos=21.4-r2-s2
Juniper Junos=21.4-r3
Juniper Junos=21.4-r3-s1
Juniper Junos=21.4-r3-s2
Juniper Junos=21.4-r3-s3
Juniper Junos=21.4-r3-s4
Juniper Junos=22.1
Juniper Junos=22.1-r1
Juniper Junos=22.1-r1-s1
Juniper Junos=22.1-r1-s2
Juniper Junos=22.1-r2
Juniper Junos=22.1-r2-s1
Juniper Junos=22.1-r2-s2
Juniper Junos=22.1-r3
Juniper Junos=22.1-r3-s1
Juniper Junos=22.1-r3-s2
Juniper Junos=22.1-r3-s3
Juniper Junos=22.2
Juniper Junos=22.2-r1
Juniper Junos=22.2-r1-s1
Juniper Junos=22.2-r1-s2
Juniper Junos=22.2-r2
Juniper Junos=22.2-r2-s1
Juniper Junos=22.2-r2-s2
Juniper Junos=22.2-r3
Juniper Junos=22.2-r3-s1
Juniper Junos=22.2-r3-s2
Juniper Junos=22.3
Juniper Junos=22.3-r1
Juniper Junos=22.3-r1-s1
Juniper Junos=22.3-r1-s2
Juniper Junos=22.3-r2
Juniper Junos=22.3-r2-s1
Juniper Junos=22.3-r2-s2
Juniper Junos=22.3-r3
Juniper Junos=22.4
Juniper Junos=22.4-r1
Juniper Junos=22.4-r1-s1
Juniper Junos=22.4-r1-s2
Juniper Junos=22.4-r2
Juniper Junos=22.4-r2-s1
Juniper Junos=23.2
Juniper Junos=23.2-r1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series and SRX Series) to a version that resolves this vulnerability.

    Fixed in 21.2R3-S6
  2. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series and SRX Series) to a version that resolves this vulnerability.

    Fixed in 21.3R3-S5
  3. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series and SRX Series) to a version that resolves this vulnerability.

    Fixed in 21.4R3-S5
  4. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series and SRX Series) to a version that resolves this vulnerability.

    Fixed in 22.1R3-S4
  5. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series and SRX Series) to a version that resolves this vulnerability.

    Fixed in 22.2R3-S3
  6. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series and SRX Series) to a version that resolves this vulnerability.

    Fixed in 22.3R3-S1
  7. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series and SRX Series) to a version that resolves this vulnerability.

    Fixed in 22.4R2-S2
  8. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series and SRX Series) to a version that resolves this vulnerability.

    Fixed in 22.4R3
  9. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series and SRX Series) to a version that resolves this vulnerability.

    Fixed in 23.2R1-S1
  10. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series and SRX Series) to a version that resolves this vulnerability.

    Fixed in 23.2R2
  11. Upgrade

    Upgrade Juniper Networks Junos OS (MX Series and SRX Series) to a version that resolves this vulnerability.

    Fixed in 23.4R1
  12. Operational

    Monitor NAT IP usage to detect impact during/after SIP ALG processing by running: show security nat resource-usage source-pool <source_pool_name> on Junos OS MX Series and SRX Series platforms.

Event History

Jan 12, 2024
CVE Published
via MITRE·12:56 AM
Data Sourced
via MITRE·12:56 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-21616?

CVE-2024-21616 has a high severity rating due to its potential to cause Denial of Service (DoS).

2

How do I fix CVE-2024-21616?

To mitigate CVE-2024-21616, it is recommended to update to the latest version of Junos OS as per Juniper's security advisory.

3

Which versions of Junos OS are affected by CVE-2024-21616?

CVE-2024-21616 affects multiple versions of Junos OS, specifically 21.2, 21.3, 21.4, 22.1, 22.2, 22.3, 22.4, and 23.2.

4

Can CVE-2024-21616 be exploited remotely?

Yes, CVE-2024-21616 can be exploited by unauthenticated network-based attackers, making it particularly dangerous.

5

What systems are impacted by CVE-2024-21616?

CVE-2024-21616 impacts Juniper Networks Junos OS running on MX Series and SRX Series platforms.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203