CVE-2024-39539: Junos OS: MX Series: Continuous subscriber logins will lead to a memory leak and eventually an FPC crash
A Missing Release of Memory after Effective Lifetime vulnerability in Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS).
In a subscriber management scenario continuous subscriber logins will trigger a memory leak and eventually lead to an FPC crash and restart.
This issue affects Junos OS on MX Series:
All version before 21.2R3-S6, 21.4 versions before 21.4R3-S6, 22.1 versions before 22.1R3-S5, 22.2 versions before 22.2R3-S3, 22.3 versions before 22.3R3-S2, 22.4 versions before 22.4R3, 23.2 versions before 23.2R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39539?
CVE-2024-39539 is classified as a Denial-of-Service (DoS) vulnerability.
How do I mitigate CVE-2024-39539?
To mitigate CVE-2024-39539, you should update your Junos OS to a version that includes the necessary fixes.
What software versions are affected by CVE-2024-39539?
CVE-2024-39539 affects Junos OS versions prior to 21.2R3-S6, 21.4R3-S6, 22.1R3-S5, 22.2R3-S3, 22.3R3-S2, 22.4R3, and 23.2R2.
Can CVE-2024-39539 be exploited remotely?
Yes, CVE-2024-39539 can be exploited by an unauthenticated adjacent attacker.
What is the impact of CVE-2024-39539 on system performance?
The impact of CVE-2024-39539 includes potential Denial-of-Service due to a memory leak triggered by continuous subscriber logins.