Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-21600
HistoryJan 12, 2024 - 1:15 a.m.

Path traversal

2024-01-1201:15:00
PRIOn knowledge base
www.prio-n.com
9
juniper networks junos os
ptx series
path traversal
denial of service
vulnerability
packet forwarding engine
mpls
fpc hang
host path wedge
log message
nvd

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.7%

An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows a unauthenticated, adjacent attacker to cause a Denial of Service (DoS).

When MPLS packets are meant to be sent to a flexible tunnel interface (FTI) and if the FTI tunnel is down, these will hit the reject NH, due to which the packets get sent to the CPU and cause a host path wedge condition. This will cause the FPC to hang and requires a manual restart to recover.

Please note that this issue specifically affects PTX1000, PTX3000, PTX5000 with FPC3, PTX10002-60C, and PTX10008/16 with LC110x. Other PTX Series devices and Line Cards (LC) are not affected.

The following log message can be seen when the issue occurs:

Cmerror Op Set: Host Loopback: HOST LOOPBACK WEDGE DETECTED IN PATH ID <id> (URI: /fpc/<fpc>/pfe/<pfe>/cm/<cm>/Host_Loopback/<cm>/HOST_LOOPBACK_MAKE_CMERROR_ID[<id>])
This issue affects Juniper Networks Junos OS:

  • All versions earlier than 20.4R3-S8;
  • 21.1 versions earlier than 21.1R3-S4;
  • 21.2 versions earlier than 21.2R3-S6;
  • 21.3 versions earlier than 21.3R3-S3;
  • 21.4 versions earlier than 21.4R3-S5;
  • 22.1 versions earlier than 22.1R2-S2, 22.1R3;
  • 22.2 versions earlier than 22.2R2-S1, 22.2R3.
Rows per page:
1-10 of 701

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.7%

Related for PRION:CVE-2024-21600