Lucene search

K
cveJuniperCVE-2024-30409
HistoryApr 12, 2024 - 3:15 p.m.

CVE-2024-30409

2024-04-1215:15:25
CWE-754
juniper
web.nvd.nist.gov
48
cve-2024-30409
improper check
unusual or exceptional conditions
telemetry processing
juniper networks
junos os
junos os evolved
authenticated attacker
forwarding information base
fibtd
crash

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVSS4

6.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

17.0%

An Improper Check for Unusual or Exceptional Conditions vulnerability in telemetry processing of Juniper Networks Junos OS and Junos OS Evolved allows a network-based authenticated attacker to cause the forwarding information base telemetry daemon (fibtd) to crash, leading to a limited Denial of Service.

This issue affects Juniper Networks

Junos OS:

  • from 22.1 before 22.1R1-S2, 22.1R2.

Junos OS Evolved:

  • from 22.1 before 22.1R1-S2-EVO, 22.1R2-EVO.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Junos OS",
    "vendor": "Juniper Networks",
    "versions": [
      {
        "lessThan": "22.1R1-S2, 22.1R2",
        "status": "affected",
        "version": "22.1",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Junos OS Evolved",
    "vendor": "Juniper Networks",
    "versions": [
      {
        "lessThan": "22.1R1-S2-EVO, 22.1R2-EVO",
        "status": "affected",
        "version": "22.1-EVO",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVSS4

6.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

17.0%

Related for CVE-2024-30409