CVE-2024-39516: Junos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crash
An Out-of-Bounds Read vulnerability in
the routing protocol daemon (rpd) of
Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.
This issue only affects systems configured in either of two ways:
systems with BGP traceoptions enabled
systems with BGP traffic engineering configured
This issue can affect iBGP and eBGP with
any address family
configured. The specific attribute involved is non-transitive, and will not propagate across a network.
This issue affects:
Junos OS:
All versions before 21.4R3-S8, 22.2 before 22.2R3-S5, 22.3 before 22.3R3-S4, 22.4 before 22.4R3-S3, 23.2 before 23.2R2-S2, 23.4 before 23.4R2;
Junos OS Evolved:
All versions before 21.4R3-S8-EVO, 22.2-EVO before 22.2R3-S5-EVO, 22.3-EVO before 22.3R3-S4-EVO, 22.4-EVO before 22.4R3-S3-EVO, 23.2-EVO before 23.2R2-S2-EVO, 23.4-EVO before 23.4R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39516?
CVE-2024-39516 is classified as a Denial of Service vulnerability.
How do I fix CVE-2024-39516?
To fix CVE-2024-39516, apply the latest security updates provided by Juniper Networks for affected versions of Junos OS and Junos OS Evolved.
What versions are affected by CVE-2024-39516?
CVE-2024-39516 affects Juniper Networks Junos OS and Junos OS Evolved versions up to 21.4R3-S8, 22.2R3-S5, 22.3R3-S4, 22.4R3-S3, 23.2R2-S2, and 23.4R2.
Can CVE-2024-39516 be exploited remotely?
Yes, CVE-2024-39516 can be exploited by unauthenticated network-based attackers.
What impact does CVE-2024-39516 have on network services?
CVE-2024-39516 can cause the routing protocol daemon (rpd) to crash and restart, leading to a temporary denial of service for network routing.