CVE-2024-21616: Junos OS: MX Series and SRX Series: Processing of a specific SIP packet causes NAT IP allocation to fail
An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).
On all Junos OS MX Series and SRX Series platforms, when SIP ALG is enabled, and a specific SIP packet is received and processed, NAT IP allocation fails for genuine traffic, which causes Denial of Service (DoS). Continuous receipt of this specific SIP ALG packet will cause a sustained DoS condition.
NAT IP usage can be monitored by running the following command.
user@srx> show security nat resource-usage source-pool <sourcepoolname>
Pool name: sourcepoolname .. Address Factor-index Port-range Used Avail Total Usage X.X.X.X 0 Single Ports 50258 52342 62464 96% <<<<< - Alg Ports 0 2048 2048 0% This issue affects:
Juniper Networks Junos OS on MX Series and SRX Series
All versions earlier than 21.2R3-S6; 21.3 versions earlier than 21.3R3-S5; 21.4 versions earlier than 21.4R3-S5; 22.1 versions earlier than 22.1R3-S4; 22.2 versions earlier than 22.2R3-S3; 22.3 versions earlier than 22.3R3-S1; 22.4 versions earlier than 22.4R2-S2, 22.4R3; 23.2 versions earlier than 23.2R1-S1, 23.2R2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos OS (MX Series and SRX Series)to a version that resolves this vulnerability.Fixed in 21.2R3-S6 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series and SRX Series)to a version that resolves this vulnerability.Fixed in 21.3R3-S5 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series and SRX Series)to a version that resolves this vulnerability.Fixed in 21.4R3-S5 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series and SRX Series)to a version that resolves this vulnerability.Fixed in 22.1R3-S4 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series and SRX Series)to a version that resolves this vulnerability.Fixed in 22.2R3-S3 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series and SRX Series)to a version that resolves this vulnerability.Fixed in 22.3R3-S1 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series and SRX Series)to a version that resolves this vulnerability.Fixed in 22.4R2-S2 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series and SRX Series)to a version that resolves this vulnerability.Fixed in 22.4R3 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series and SRX Series)to a version that resolves this vulnerability.Fixed in 23.2R1-S1 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series and SRX Series)to a version that resolves this vulnerability.Fixed in 23.2R2 - Upgrade
Upgrade
Juniper Networks Junos OS (MX Series and SRX Series)to a version that resolves this vulnerability.Fixed in 23.4R1 - Operational
Monitor NAT IP usage to detect impact during/after SIP ALG processing by running: show security nat resource-usage source-pool <source_pool_name> on Junos OS MX Series and SRX Series platforms.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21616?
CVE-2024-21616 has a high severity rating due to its potential to cause Denial of Service (DoS).
How do I fix CVE-2024-21616?
To mitigate CVE-2024-21616, it is recommended to update to the latest version of Junos OS as per Juniper's security advisory.
Which versions of Junos OS are affected by CVE-2024-21616?
CVE-2024-21616 affects multiple versions of Junos OS, specifically 21.2, 21.3, 21.4, 22.1, 22.2, 22.3, 22.4, and 23.2.
Can CVE-2024-21616 be exploited remotely?
Yes, CVE-2024-21616 can be exploited by unauthenticated network-based attackers, making it particularly dangerous.
What systems are impacted by CVE-2024-21616?
CVE-2024-21616 impacts Juniper Networks Junos OS running on MX Series and SRX Series platforms.