跳转到帖子

Juniper Junos OS: 2024-04 Security Bulletin: Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash (JSA75739) (CVE-2024-21598)

recommended_posts

发布于
  • Members

Juniper Junos OS: 2024-04 Security Bulletin: Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash (JSA75739) (CVE-2024-21598)

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
04/10/2024
Created
04/11/2024
Added
04/11/2024
Modified
05/20/2024

Description

An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute with a specifically malformed TLV, rpd will crash and restart. This issue affects Juniper Networks Junos OS: *20.4 versions 20.4R1 and later versions earlier than 20.4R3-S9; *21.2 versions earlier than 21.2R3-S7; *21.3 versions earlier than 21.3R3-S5; *21.4 versions earlier than 21.4R3-S5; *22.1 versions earlier than 22.1R3-S4; *22.2 versions earlier than 22.2R3-S3; *22.3 versions earlier than 22.3R3-S1; *22.4 versions earlier than 22.4R3; *23.2 versions earlier than 23.2R1-S2, 23.2R2; Junos OS Evolved: *20.4-EVO versions 20.4R1-EVO and later versions earlier than 20.4R3-S9-EVO; *21.2-EVO versions earlier than 21.2R3-S7-EVO; *21.3-EVO versions earlier than 21.3R3-S5-EVO; *21.4-EVO versions earlier than 21.4R3-S5-EVO; *22.1-EVO versions earlier than 22.1R3-S4-EVO; *22.2-EVO versions earlier than 22.2R3-S3-EVO; *22.3-EVO versions earlier than 22.3R3-S1-EVO; *22.4-EVO versions earlier than 22.4R3-EVO; *23.2-EVO versions earlier than 23.2R1-S2-EVO, 23.2R2-EVO; This issue does not affect Juniper Networks *Junos OS versions earlier than 20.4R1; *Junos OS Evolved versions earlier than 20.4R1-EVO. This is a related but separate issue than the one described in JSA79095.

Solution(s)

  • juniper-junos-os-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2024-21598
  • CVE - 2024-21598
  • JSA75739
  • 查看数 714
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…