CVE-2024-47489: Junos OS Evolved: ACX Series: Receipt of specific transit protocol packets is incorrectly processed by the RE

Published Oct 11, 2024
·
Updated

An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices allows an unauthenticated, network based attacker sending specific transit protocol traffic to cause a partial Denial of Service (DoS) to downstream devices.

Receipt of specific transit protocol packets is incorrectly processed by the Routing Engine (RE), filling up the DDoS protection queue which is shared between routing protocols. This influx of transit protocol packets causes DDoS protection violations, resulting in protocol flaps which can affect connectivity to networking devices.

This issue affects both IPv4 and IPv6. This issue does not require any specific routing protocol to be configured or enabled.

The following commands can be used to monitor the DDoS protection queue:

labuser@re0> show evo-pfemand host pkt-stats

labuser@re0> show host-path ddos all-policers

This issue affects Junos OS Evolved:

All versions before 21.4R3-S8-EVO,  from 22.2 before 22.2R3-S4-EVO,  from 22.3 before 22.3R3-S4-EVO,  from 22.4 before 22.4R3-S3-EVO,  from 23.2 before 23.2R2-EVO,  from 23.4 before 23.4R1-S1-EVO, 23.4R2-EVO,  from 24.2 before 24.2R2-EVO.

Other sources

An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices allows an unauthenticated, network based attacker sending specific transit protocol traffic to cause a partial Denial of Service (DoS) to downstream devices.

Receipt of specific transit protocol packets is incorrectly processed by the Routing Engine (RE), filling up the DDoS protection queue which is shared between routing protocols. This influx of transit protocol packets causes DDoS protection violations, resulting in protocol flaps which can affect connectivity to networking devices.

This issue affects both IPv4 and IPv6. This issue does not require any specific routing protocol to be configured or enabled.

The following commands can be used to monitor the DDoS protection queue:

labuser@re0> show evo-pfemand host pkt-stats

??  labuser@re0> show host-path ddos all-policers

This issue affects Junos OS Evolved:

All versions before 21.4R3-S8-EVO,  from 22.2 before 22.2R3-S4-EVO,  from 22.3 before 22.3R3-S4-EVO,  from 22.4 before 22.4R3-S3-EVO,  from 23.2 before 23.2R2-EVO,  from 23.4 before 23.4R1-S1-EVO, 23.4R2-EVO,  from 24.2 before 24.2R2-EVO.

NVD

Affected Software

69 affected components
Juniper Networks Junos OS Evolved
All of the following
Any of the following
Juniper Junos OS Evolved<21.4
Juniper Junos OS Evolved=21.4
Juniper Junos OS Evolved=21.4-r1
Juniper Junos OS Evolved=21.4-r1-s1
Juniper Junos OS Evolved=21.4-r1-s2
Juniper Junos OS Evolved=21.4-r2
Juniper Junos OS Evolved=21.4-r2-s1
Juniper Junos OS Evolved=21.4-r2-s2
Juniper Junos OS Evolved=21.4-r3
Juniper Junos OS Evolved=21.4-r3-s1
Juniper Junos OS Evolved=21.4-r3-s2
Juniper Junos OS Evolved=21.4-r3-s3
Juniper Junos OS Evolved=21.4-r3-s4
Juniper Junos OS Evolved=21.4-r3-s5
Juniper Junos OS Evolved=21.4-r3-s6
Juniper Junos OS Evolved=21.4-r3-s7
Juniper Junos OS Evolved=22.2
Juniper Junos OS Evolved=22.2-r1
Juniper Junos OS Evolved=22.2-r1-s1
Juniper Junos OS Evolved=22.2-r1-s2
Juniper Junos OS Evolved=22.2-r2
Juniper Junos OS Evolved=22.2-r2-s1
Juniper Junos OS Evolved=22.2-r2-s2
Juniper Junos OS Evolved=22.2-r3
Juniper Junos OS Evolved=22.2-r3-s1
Juniper Junos OS Evolved=22.2-r3-s2
Juniper Junos OS Evolved=22.2-r3-s3
Juniper Junos OS Evolved=22.3
Juniper Junos OS Evolved=22.3-r1
Juniper Junos OS Evolved=22.3-r1-s1
Juniper Junos OS Evolved=22.3-r1-s2
Juniper Junos OS Evolved=22.3-r2
Juniper Junos OS Evolved=22.3-r2-s1
Juniper Junos OS Evolved=22.3-r2-s2
Juniper Junos OS Evolved=22.3-r3
Juniper Junos OS Evolved=22.3-r3-s1
Juniper Junos OS Evolved=22.3-r3-s2
Juniper Junos OS Evolved=22.3-r3-s3
Juniper Junos OS Evolved=22.4
Juniper Junos OS Evolved=22.4-r1
Juniper Junos OS Evolved=22.4-r1-s1
Juniper Junos OS Evolved=22.4-r1-s2
Juniper Junos OS Evolved=22.4-r2
Juniper Junos OS Evolved=22.4-r2-s1
Juniper Junos OS Evolved=22.4-r2-s2
Juniper Junos OS Evolved=22.4-r3
Juniper Junos OS Evolved=22.4-r3-s1
Juniper Junos OS Evolved=22.4-r3-s2
Juniper Junos OS Evolved=23.2
Juniper Junos OS Evolved=23.2-r1
Juniper Junos OS Evolved=23.2-r1-s1
Juniper Junos OS Evolved=23.2-r1-s2
Juniper Junos OS Evolved=23.4
Juniper Junos OS Evolved=23.4-r1
Juniper Junos OS Evolved=23.4-r2
Juniper Junos OS Evolved=24.2
Juniper Junos OS Evolved=24.2-r1
Juniper Junos OS Evolved=24.2-r1-s2
Any of the following
Juniper ACX5448
Juniper Acx5448-d
Juniper Acx5448-m
Juniper Acx7020
Juniper ACX7024
Juniper ACX7024X
Juniper ACX710
Juniper Acx7100
Juniper Acx7300
Juniper ACX7509

Remediation

Information

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 21.4R3-S8-EVO, 22.2R3-S4-EVO, 22.3R3-S4-EVO*, 22.4R3-S3-EVO, 23.2R2-EVO, 23.4R1-S1-EVO, 23.4R2-EVO, 24.2R2-EVO*, 24.4R1-EVO*, and all subsequent releases. * Future Release

Event History

Oct 11, 2024
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-47489?

CVE-2024-47489 has been assigned a high severity rating due to its potential to cause denial of service.

2

How do I fix CVE-2024-47489?

To mitigate CVE-2024-47489, users should upgrade to the latest version of Junos OS Evolved that addresses this vulnerability.

3

Who is affected by CVE-2024-47489?

CVE-2024-47489 affects Juniper Networks Junos OS Evolved on ACX Series devices prior to version 21.4R3-S8-EVO.

4

What kind of attack does CVE-2024-47489 allow?

CVE-2024-47489 allows an unauthenticated network-based attacker to send specific transit protocol traffic that could lead to partial Denial of Service.

5

When was CVE-2024-47489 reported?

CVE-2024-47489 was reported in 2024 as a vulnerability affecting the Packet Forwarding Engine of Junos OS Evolved.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203