CVE-2024-30392: Junos OS: MX Series with SPC3 and MS-MPC/-MIC: When URL filtering is enabled and a specific URL request is received a flowd crash occurs
A Stack-based Buffer Overflow vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).
On all Junos OS MX Series platforms with SPC3 and MS-MPC/-MIC, when URL filtering is enabled and a specific URL request is received and processed, flowd will crash and restart. Continuous reception of the specific URL request will lead to a sustained Denial of Service (DoS) condition.
This issue affects: Junos OS:
all versions before 21.2R3-S6,
from 21.3 before 21.3R3-S5,
from 21.4 before 21.4R3-S5,
from 22.1 before 22.1R3-S3,
from 22.2 before 22.2R3-S1,
from 22.3 before 22.3R2-S2, 22.3R3,
from 22.4 before 22.4R2-S1, 22.4R3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30392?
The severity of CVE-2024-30392 is considered critical due to its potential to cause Denial of Service (DoS) in affected systems.
How do I fix CVE-2024-30392?
To mitigate CVE-2024-30392, it is recommended to upgrade Junos OS to a patched version beyond 21.2R3-S6 and avoid enabling URL filtering if possible.
Which devices are affected by CVE-2024-30392?
CVE-2024-30392 affects all Junos OS MX Series platforms with SPC3 and MS-MPC/-MIC when URL filtering is enabled.
Can CVE-2024-30392 be exploited remotely?
Yes, CVE-2024-30392 can be exploited remotely by unauthenticated attackers over the network.
What is the impact of CVE-2024-30392 on Juniper Networks products?
The impact of CVE-2024-30392 is a potential Denial of Service (DoS), causing affected systems to become unresponsive.