CVE-2024-39529: Junos OS: SRX Series: If DNS traceoptions are configured in a DGA or tunnel detection scenario specific DNS traffic leads to a PFE crash
A Use of Externally-Controlled Format String vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
If DNS Domain Generation Algorithm (DGA) detection or tunnel detection, and DNS-filtering traceoptions are configured, and specific valid transit DNS traffic is received this causes a PFE crash and restart, leading to a Denial of Service.
This issue affects Junos OS: All versions before 21.4R3-S6, 22.2 versions before 22.2R3-S3, 22.3 versions before 22.3R3-S3, 22.4 versions before 22.4R3, 23.2 versions before 23.2R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39529?
CVE-2024-39529 is classified as a Denial-of-Service vulnerability, allowing an unauthenticated attacker to disrupt service.
How do I fix CVE-2024-39529?
To fix CVE-2024-39529, update your Juniper Networks Junos OS to a patched version that addresses this vulnerability.
Which versions of Junos OS are affected by CVE-2024-39529?
CVE-2024-39529 affects Juniper Networks Junos OS versions up to 21.4 and various versions in the 22.x and 23.x series.
What impact does CVE-2024-39529 have on my network?
Exploitation of CVE-2024-39529 can lead to a Denial-of-Service condition, making it impossible for legitimate users to access network services.
Is CVE-2024-39529 an authenticated or unauthenticated vulnerability?
CVE-2024-39529 is an unauthenticated vulnerability, meaning it can be exploited without user credentials.