CVE-2024-39541: Junos OS and Junos OS Evolved: Inconsistent information in the TE database can lead to an rpd crash
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).
When conflicting information (IP or ISO addresses) about a node is added to the Traffic Engineering (TE) database and then a subsequent operation attempts to process these, rpd will crash and restart.
This issue affects:
Junos OS:
22.4 versions before 22.4R3-S1, 23.2 versions before 23.2R2, 23.4 versions before 23.4R1-S1, 23.4R2,
This issue does not affect Junos OS versions earlier than 22.4R1.
Junos OS Evolved:
22.4-EVO versions before 22.4R3-S2-EVO, 23.2-EVO versions before 23.2R2-EVO, 23.4-EVO versions before 23.4R1-S1-EVO, 23.4R2-EVO,
This issue does not affect Junos OS Evolved versions earlier than
before 22.4R1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39541?
CVE-2024-39541 has been classified as a medium severity vulnerability due to its potential to cause a Denial-of-Service (DoS) condition.
How do I fix CVE-2024-39541?
To resolve CVE-2024-39541, update Junos OS or Junos OS Evolved to a version that is not affected by the vulnerability.
What systems are affected by CVE-2024-39541?
CVE-2024-39541 affects various versions of Juniper Networks Junos OS and Junos OS Evolved.
Who can exploit CVE-2024-39541?
An unauthenticated, adjacent attacker can exploit CVE-2024-39541 to cause a Denial-of-Service condition.
What type of vulnerability is CVE-2024-39541?
CVE-2024-39541 is classified as an Improper Handling of Exceptional Conditions vulnerability.