CVE-2024-30401: Junos OS: MX Series and EX9200-15C: Stack-based buffer overflow in aftman
An Out-of-bounds Read vulnerability in the advanced forwarding management process aftman of Juniper Networks Junos OS on MX Series with MPC10E, MPC11, MX10K-LC9600 line cards, MX304, and EX9200-15C, may allow an attacker to exploit a stack-based buffer overflow, leading to a reboot of the FPC.
Through code review, it was determined that the interface definition code for aftman could read beyond a buffer boundary, leading to a stack-based buffer overflow. This issue affects Junos OS on MX Series and EX9200-15C:
from 21.2 before 21.2R3-S1, from 21.4 before 21.4R3, from 22.1 before 22.1R2, from 22.2 before 22.2R2;
This issue does not affect:
versions of Junos OS prior to 20.3R1; any version of Junos OS 20.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30401?
CVE-2024-30401 has a high severity rating due to the potential for a stack-based buffer overflow leading to a system reboot.
How do I fix CVE-2024-30401?
To mitigate CVE-2024-30401, update your Junos OS to the latest version released by Juniper Networks that addresses this vulnerability.
Which devices are affected by CVE-2024-30401?
CVE-2024-30401 affects Juniper Networks Junos OS on MX Series with MPC10E, MPC11, MX10K-LC9600 line cards, MX304, and EX9200-15C.
Can CVE-2024-30401 be exploited remotely?
Yes, an attacker can exploit CVE-2024-30401 remotely, making it a significant risk if the device is exposed to untrusted networks.
What type of vulnerability is CVE-2024-30401?
CVE-2024-30401 is categorized as an Out-of-bounds Read vulnerability.