跳转到帖子

Juniper Junos OS: 2024-01 Security Bulletin: Junos OS and Junos OS Evolved: A specific query via DREND causes rpd crash (JSA75755) (CVE-2024-21614)

recommended_posts

发布于
  • Members

Juniper Junos OS: 2024-01 Security Bulletin: Junos OS and Junos OS Evolved: A specific query via DREND causes rpd crash (JSA75755) (CVE-2024-21614)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
01/10/2024
Created
01/12/2024
Added
01/11/2024
Modified
01/28/2025

Description

An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause rpd to crash, leading to Denial of Service (DoS). On all Junos OS and Junos OS Evolved platforms, when NETCONF and gRPC are enabled, and a specific query is executed via Dynamic Rendering (DREND), rpd will crash and restart. Continuous execution of this specific query will cause a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS *22.2 versions earlier than 22.2R2-S2, 22.2R3; *22.3 versions earlier than 22.3R2, 22.3R3. Juniper Networks Junos OS Evolved *22.2 versions earlier than 22.2R2-S2-EVO, 22.2R3-EVO; *22.3 versions earlier than 22.3R2-EVO, 22.3R3-EVO. This issue does not affect Juniper Networks: Junos OS versions earlier than 22.2R1; Junos OS Evolved versions earlier than 22.2R1-EVO.

Solution(s)

  • juniper-junos-os-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2024-21614
  • CVE - 2024-21614
  • JSA75755
  • 查看数 704
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…