CVE-2024-30402: Junos OS and Junos OS Evolved: The l2ald crashes on receiving telemetry messages from a specific subscription
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).
When telemetry requests are sent to the device, and the Dynamic Rendering Daemon (drend) is suspended, the l2ald crashes and restarts due to factors outside the attackers control. Repeated occurrences of these events causes a sustained DoS condition.
This issue affects: Junos OS: All versions earlier than 20.4R3-S10; 21.2 versions earlier than 21.2R3-S7; 21.4 versions earlier than 21.4R3-S5; 22.1 versions earlier than 22.1R3-S4; 22.2 versions earlier than 22.2R3-S3; 22.3 versions earlier than 22.3R3-S1; 22.4 versions earlier than 22.4R3; 23.2 versions earlier than 23.2R1-S2, 23.2R2.
Junos OS Evolved:
All versions earlier than 21.4R3-S5-EVO; 22.1-EVO versions earlier than 22.1R3-S4-EVO; 22.2-EVO versions earlier than 22.2R3-S3-EVO; 22.3-EVO versions earlier than 22.3R3-S1-EVO; 22.4-EVO versions earlier than 22.4R3-EVO; 23.2-EVO versions earlier than 23.2R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30402?
CVE-2024-30402 has a High severity rating due to its potential to cause a Denial of Service (DoS) in affected systems.
How do I fix CVE-2024-30402?
To fix CVE-2024-30402, ensure that you upgrade to the recommended secure versions of the Junos OS or Junos OS Evolved as specified by Juniper Networks.
What products are affected by CVE-2024-30402?
CVE-2024-30402 affects multiple versions of Juniper Networks Junos OS and Junos OS Evolved, including versions up to 23.2-R2.
Can CVE-2024-30402 be exploited remotely?
CVE-2024-30402 requires an adjacent attacker to exploit the vulnerability, meaning remote exploitation is not possible.
What are the potential impacts of CVE-2024-30402?
The potential impact of CVE-2024-30402 includes a Denial of Service (DoS), which may disrupt service availability for affected devices.