
11/7/2024

5/3/2025
CVE-2024-39539: Junos OS: MX Series: Continuous subscriber logins will lead to a memory leak and eventually an FPC crash
First published: Thu Jul 11 2024(Updated: )
A Missing Release of Memory after Effective Lifetime vulnerability in Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS).
In a subscriber management scenario continuous subscriber logins will trigger a memory leak and eventually lead to an FPC crash and restart.
This issue affects Junos OS on MX Series:
* All version before 21.2R3-S6,
* 21.4 versions before 21.4R3-S6,
* 22.1 versions before 22.1R3-S5,
* 22.2 versions before 22.2R3-S3,
* 22.3 versions before 22.3R3-S2,
* 22.4 versions before 22.4R3,
* 23.2 versions before 23.2R2.
Credit: sirt@juniper.net
Affected Software | Affected Version | How to fix |
---|
All of | | |
Any of | | |
Junos OS Evolved | <21.2 | |
Junos OS Evolved | =21.2 | |
Junos OS Evolved | =21.2-r1 | |
Junos OS Evolved | =21.2-r1-s1 | |
Junos OS Evolved | =21.2-r1-s2 | |
Junos OS Evolved | =21.2-r2 | |
Junos OS Evolved | =21.2-r2-s1 | |
Junos OS Evolved | =21.2-r2-s2 | |
Junos OS Evolved | =21.2-r3 | |
Junos OS Evolved | =21.2-r3-s1 | |
Junos OS Evolved | =21.2-r3-s2 | |
Junos OS Evolved | =21.2-r3-s3 | |
Junos OS Evolved | =21.2-r3-s4 | |
Junos OS Evolved | =21.2-r3-s5 | |
Junos OS Evolved | =21.4 | |
Junos OS Evolved | =21.4-r1 | |
Junos OS Evolved | =21.4-r1-s1 | |
Junos OS Evolved | =21.4-r1-s2 | |
Junos OS Evolved | =21.4-r2 | |
Junos OS Evolved | =21.4-r2-s1 | |
Junos OS Evolved | =21.4-r2-s2 | |
Junos OS Evolved | =21.4-r3 | |
Junos OS Evolved | =21.4-r3-s1 | |
Junos OS Evolved | =21.4-r3-s2 | |
Junos OS Evolved | =21.4-r3-s3 | |
Junos OS Evolved | =21.4-r3-s4 | |
Junos OS Evolved | =21.4-r3-s5 | |
Junos OS Evolved | =22.1 | |
Junos OS Evolved | =22.1-r1 | |
Junos OS Evolved | =22.1-r1-s1 | |
Junos OS Evolved | =22.1-r1-s2 | |
Junos OS Evolved | =22.1-r2 | |
Junos OS Evolved | =22.1-r2-s1 | |
Junos OS Evolved | =22.1-r2-s2 | |
Junos OS Evolved | =22.1-r3 | |
Junos OS Evolved | =22.1-r3-s1 | |
Junos OS Evolved | =22.1-r3-s2 | |
Junos OS Evolved | =22.1-r3-s3 | |
Junos OS Evolved | =22.1-r3-s4 | |
Junos OS Evolved | =22.2 | |
Junos OS Evolved | =22.2-r1 | |
Junos OS Evolved | =22.2-r1-s1 | |
Junos OS Evolved | =22.2-r1-s2 | |
Junos OS Evolved | =22.2-r2 | |
Junos OS Evolved | =22.2-r2-s1 | |
Junos OS Evolved | =22.2-r2-s2 | |
Junos OS Evolved | =22.2-r3 | |
Junos OS Evolved | =22.2-r3-s1 | |
Junos OS Evolved | =22.2-r3-s2 | |
Junos OS Evolved | =22.3 | |
Junos OS Evolved | =22.3-r1 | |
Junos OS Evolved | =22.3-r1-s1 | |
Junos OS Evolved | =22.3-r1-s2 | |
Junos OS Evolved | =22.3-r2 | |
Junos OS Evolved | =22.3-r2-s1 | |
Junos OS Evolved | =22.3-r2-s2 | |
Junos OS Evolved | =22.3-r3 | |
Junos OS Evolved | =22.3-r3-s1 | |
Junos OS Evolved | =22.4 | |
Junos OS Evolved | =22.4-r1 | |
Junos OS Evolved | =22.4-r1-s1 | |
Junos OS Evolved | =22.4-r1-s2 | |
Junos OS Evolved | =22.4-r2 | |
Junos OS Evolved | =22.4-r2-s1 | |
Junos OS Evolved | =22.4-r2-s2 | |
Junos OS Evolved | =23.2 | |
Junos OS Evolved | =23.2-r1 | |
Junos OS Evolved | =23.2-r1-s1 | |
Junos OS Evolved | =23.2-r1-s2 | |
Any of | | |
Juniper MX Series | | |
Juniper MX10 | | |
Juniper MX10000 | | |
Juniper MX10003 | | |
Juniper MX10004 | | |
Juniper MX10008 | | |
Juniper MX10016 | | |
Juniper MX104 | | |
Juniper MX150 | | |
Juniper MX2008 | | |
Juniper MX2010 | | |
Juniper MX2020 | | |
Juniper MX204 | | |
Juniper MX240 | | |
Juniper MX304 | | |
Juniper MX40 | | |
Juniper MX480 | | |
Juniper MX5 | | |
Juniper MX80 | | |
Juniper MX960 | | |
Juniper JUNOS | <21.2R3-S6<21.4R3-S6<22.1R3-S5<22.2R3-S3<22.3R3-S2<22.4R3<23.2R2 | |
Remedy
The following software releases have been updated to resolve this specific issue: 21.2R3-S6, 21.4R3-S6, 22.1R3-S5, 22.2R3-S3, 22.3R3-S2, 22.4R3, 23.2R2, 23.4R1, and all subsequent releases.
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is the severity of CVE-2024-39539?
CVE-2024-39539 is classified as a Denial-of-Service (DoS) vulnerability.
How do I mitigate CVE-2024-39539?
To mitigate CVE-2024-39539, you should update your Junos OS to a version that includes the necessary fixes.
What software versions are affected by CVE-2024-39539?
CVE-2024-39539 affects Junos OS versions prior to 21.2R3-S6, 21.4R3-S6, 22.1R3-S5, 22.2R3-S3, 22.3R3-S2, 22.4R3, and 23.2R2.
Can CVE-2024-39539 be exploited remotely?
Yes, CVE-2024-39539 can be exploited by an unauthenticated adjacent attacker.
What is the impact of CVE-2024-39539 on system performance?
The impact of CVE-2024-39539 includes potential Denial-of-Service due to a memory leak triggered by continuous subscriber logins.
- agent/references
- agent/remedy
- agent/weakness
- agent/title
- agent/type
- agent/description
- agent/first-publish-date
- agent/severity
- agent/author
- collector/mitre-cve
- source/MITRE
- agent/source
- agent/guess-ai
- agent/software-canonical-lookup
- agent/software-canonical-lookup-request
- agent/last-modified-date
- agent/softwarecombine
- agent/tags
- agent/event
- collector/nvd-api
- source/NVD
- vendor/juniper networks
- canonical/juniper junos
- vendor/juniper
- canonical/junos os evolved
- version/junos os evolved/21.2
- version/junos os evolved/21.2-r1
- version/junos os evolved/21.2-r1-s1
- version/junos os evolved/21.2-r1-s2
- version/junos os evolved/21.2-r2
- version/junos os evolved/21.2-r2-s1
- version/junos os evolved/21.2-r2-s2
- version/junos os evolved/21.2-r3
- version/junos os evolved/21.2-r3-s1
- version/junos os evolved/21.2-r3-s2
- version/junos os evolved/21.2-r3-s3
- version/junos os evolved/21.2-r3-s4
- version/junos os evolved/21.2-r3-s5
- version/junos os evolved/21.4
- version/junos os evolved/21.4-r1
- version/junos os evolved/21.4-r1-s1
- version/junos os evolved/21.4-r1-s2
- version/junos os evolved/21.4-r2
- version/junos os evolved/21.4-r2-s1
- version/junos os evolved/21.4-r2-s2
- version/junos os evolved/21.4-r3
- version/junos os evolved/21.4-r3-s1
- version/junos os evolved/21.4-r3-s2
- version/junos os evolved/21.4-r3-s3
- version/junos os evolved/21.4-r3-s4
- version/junos os evolved/21.4-r3-s5
- version/junos os evolved/22.1
- version/junos os evolved/22.1-r1
- version/junos os evolved/22.1-r1-s1
- version/junos os evolved/22.1-r1-s2
- version/junos os evolved/22.1-r2
- version/junos os evolved/22.1-r2-s1
- version/junos os evolved/22.1-r2-s2
- version/junos os evolved/22.1-r3
- version/junos os evolved/22.1-r3-s1
- version/junos os evolved/22.1-r3-s2
- version/junos os evolved/22.1-r3-s3
- version/junos os evolved/22.1-r3-s4
- version/junos os evolved/22.2
- version/junos os evolved/22.2-r1
- version/junos os evolved/22.2-r1-s1
- version/junos os evolved/22.2-r1-s2
- version/junos os evolved/22.2-r2
- version/junos os evolved/22.2-r2-s1
- version/junos os evolved/22.2-r2-s2
- version/junos os evolved/22.2-r3
- version/junos os evolved/22.2-r3-s1
- version/junos os evolved/22.2-r3-s2
- version/junos os evolved/22.3
- version/junos os evolved/22.3-r1
- version/junos os evolved/22.3-r1-s1
- version/junos os evolved/22.3-r1-s2
- version/junos os evolved/22.3-r2
- version/junos os evolved/22.3-r2-s1
- version/junos os evolved/22.3-r2-s2
- version/junos os evolved/22.3-r3
- version/junos os evolved/22.3-r3-s1
- version/junos os evolved/22.4
- version/junos os evolved/22.4-r1
- version/junos os evolved/22.4-r1-s1
- version/junos os evolved/22.4-r1-s2
- version/junos os evolved/22.4-r2
- version/junos os evolved/22.4-r2-s1
- version/junos os evolved/22.4-r2-s2
- version/junos os evolved/23.2
- version/junos os evolved/23.2-r1
- version/junos os evolved/23.2-r1-s1
- version/junos os evolved/23.2-r1-s2
- canonical/juniper mx series
- canonical/juniper mx10
- canonical/juniper mx10000
- canonical/juniper mx10003
- canonical/juniper mx10004
- canonical/juniper mx10008
- canonical/juniper mx10016
- canonical/juniper mx104
- canonical/juniper mx150
- canonical/juniper mx2008
- canonical/juniper mx2010
- canonical/juniper mx2020
- canonical/juniper mx204
- canonical/juniper mx240
- canonical/juniper mx304
- canonical/juniper mx40
- canonical/juniper mx480
- canonical/juniper mx5
- canonical/juniper mx80
- canonical/juniper mx960
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203