VYPR
Unrated severityNVD Advisory· Published Apr 12, 2024· Updated Aug 2, 2024

Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash

CVE-2024-30395

Description

An Improper Validation of Specified Type of Input vulnerability in Routing Protocol Daemon (RPD) of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).

If a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute with a specifically malformed TLV, rpd will crash and restart. This issue affects:

Junos OS:

  • all versions before 21.2R3-S7,
  • from 21.3 before 21.3R3-S5,
  • from 21.4 before 21.4R3-S5,
  • from 22.1 before 22.1R3-S5,
  • from 22.2 before 22.2R3-S3,
  • from 22.3 before 22.3R3-S2,
  • from 22.4 before 22.4R3,
  • from 23.2 before 23.2R1-S2, 23.2R2.

Junos OS Evolved:

  • all versions before 21.2R3-S7-EVO,
  • from 21.3-EVO before 21.3R3-S5-EVO,
  • from 21.4-EVO before 21.4R3-S5-EVO,
  • from 22.2-EVO before 22.2R3-S3-EVO,
  • from 22.3-EVO before 22.3R3-S2-EVO,
  • from 22.4-EVO before 22.4R3-EVO,
  • from 23.2-EVO before 23.2R1-S2-EVO, 23.2R2-EVO.

This is a related but separate issue than the one described in JSA75739

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • all versions before 21.2R3-S7-EVO, from 21.3-EVO before 21.3R3-S5-EVO, from 21.4-EVO before 21.4R3-S5-EVO, from 22.2-EVO before 22.2R3-S3-EVO, from 22.3-EVO before 22.3R3-S2-EVO, from 22.4-EVO before 22.4R3-EVO, from 23.2-EVO before 23.2R1-S2-EVO, 23.2R2-EVO+ 1 more
    • (no CPE)range: all versions before 21.2R3-S7-EVO, from 21.3-EVO before 21.3R3-S5-EVO, from 21.4-EVO before 21.4R3-S5-EVO, from 22.2-EVO before 22.2R3-S3-EVO, from 22.3-EVO before 22.3R3-S2-EVO, from 22.4-EVO before 22.4R3-EVO, from 23.2-EVO before 23.2R1-S2-EVO, 23.2R2-EVO
    • (no CPE)range: 0
  • Range: all versions before 21.2R3-S7, from 21.3 before 21.3R3-S5, from 21.4 before 21.4R3-S5, from 22.1 before 22.1R3-S5, from 22.2 before 22.2R3-S3, from 22.3 before 22.3R3-S2, from 22.4 before 22.4R3, from 23.2 before 23.2R1-S2, 23.2R2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.