CVE-2024-30394: Junos OS and Junos OS Evolved: A specific EVPN type-5 route causes rpd crash
A Stack-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) component of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an rpd crash, leading to Denial of Service (DoS).
On all Junos OS and Junos OS Evolved platforms, when EVPN is configured, and a specific EVPN type-5 route is received via BGP, rpd crashes and restarts. Continuous receipt of this specific route will lead to a sustained Denial of Service (DoS) condition.
This issue affects: Junos OS:
all versions before 21.2R3-S7,
from 21.4 before 21.4R3-S5,
from 22.1 before 22.1R3-S4,
from 22.2 before 22.2R3-S2,
from 22.3 before 22.3R3-S1,
from 22.4 before 22.4R3,
from 23.2 before 23.2R2.
Junos OS Evolved:
all versions before 21.4R3-S5-EVO,
from 22.1-EVO before 22.1R3-S4-EVO,
from 22.2-EVO before 22.2R3-S2-EVO,
from 22.3-EVO before 22.3R3-S1-EVO,
from 22.4-EVO before 22.4R3-EVO,
from 23.2-EVO before 23.2R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30394?
CVE-2024-30394 has a high severity rating due to its potential to cause Denial of Service (DoS) through a stack-based buffer overflow.
How do I fix CVE-2024-30394?
To fix CVE-2024-30394, users should upgrade to versions of Junos OS greater than 21.2R3-S7 and Junos OS Evolved greater than 21.4R3-S5-EVO.
What products are affected by CVE-2024-30394?
CVE-2024-30394 affects Juniper's Junos OS and Junos OS Evolved up to specific versions as noted in the vulnerability announcement.
Can CVE-2024-30394 be exploited remotely?
Yes, CVE-2024-30394 can be exploited by unauthenticated, network-based attackers.
What impact does CVE-2024-30394 have on systems?
The impact of CVE-2024-30394 is a crash of the Routing Protocol Daemon (RPD), leading to a Denial of Service on affected systems.