Unrated severityNVD Advisory· Published Apr 12, 2024· Updated Aug 2, 2024
Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash
CVE-2024-30395
Description
An Improper Validation of Specified Type of Input vulnerability in Routing Protocol Daemon (RPD) of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).
If a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute with a specifically malformed TLV, rpd will crash and restart. This issue affects:
Junos OS:
- all versions before 21.2R3-S7,
- from 21.3 before 21.3R3-S5,
- from 21.4 before 21.4R3-S5,
- from 22.1 before 22.1R3-S5,
- from 22.2 before 22.2R3-S3,
- from 22.3 before 22.3R3-S2,
- from 22.4 before 22.4R3,
- from 23.2 before 23.2R1-S2, 23.2R2.
Junos OS Evolved:
- all versions before 21.2R3-S7-EVO,
- from 21.3-EVO before 21.3R3-S5-EVO,
- from 21.4-EVO before 21.4R3-S5-EVO,
- from 22.2-EVO before 22.2R3-S3-EVO,
- from 22.3-EVO before 22.3R3-S2-EVO,
- from 22.4-EVO before 22.4R3-EVO,
- from 23.2-EVO before 23.2R1-S2-EVO, 23.2R2-EVO.
This is a related but separate issue than the one described in JSA75739
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3all versions before 21.2R3-S7-EVO, from 21.3-EVO before 21.3R3-S5-EVO, from 21.4-EVO before 21.4R3-S5-EVO, from 22.2-EVO before 22.2R3-S3-EVO, from 22.3-EVO before 22.3R3-S2-EVO, from 22.4-EVO before 22.4R3-EVO, from 23.2-EVO before 23.2R1-S2-EVO, 23.2R2-EVO+ 1 more
- (no CPE)range: all versions before 21.2R3-S7-EVO, from 21.3-EVO before 21.3R3-S5-EVO, from 21.4-EVO before 21.4R3-S5-EVO, from 22.2-EVO before 22.2R3-S3-EVO, from 22.3-EVO before 22.3R3-S2-EVO, from 22.4-EVO before 22.4R3-EVO, from 23.2-EVO before 23.2R1-S2-EVO, 23.2R2-EVO
- (no CPE)range: 0
- Range: all versions before 21.2R3-S7, from 21.3 before 21.3R3-S5, from 21.4 before 21.4R3-S5, from 22.1 before 22.1R3-S5, from 22.2 before 22.2R3-S3, from 22.3 before 22.3R3-S2, from 22.4 before 22.4R3, from 23.2 before 23.2R1-S2, 23.2R2
Patches
Vulnerability mechanics
References
2- supportportal.juniper.net/JSA79095mitrevendor-advisory
- www.first.org/cvss/calculator/4.0mitretechnical-description
News mentions
0No linked articles in our index yet.