An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on SRX Series, and MX Series with SPC3 allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
When an affected device receives specific valid TCP traffic, the pfe crashes and restarts leading to a momentary but complete service outage.
This issue affects Junos OS:
21.2 releases from 21.2R3-S5 before 21.2R3-S6.
This issue does not affect earlier or later releases.
References
Link | Resource |
---|---|
https://supportportal.juniper.net/JSA83000 | Vendor Advisory |
https://supportportal.juniper.net/JSA83000 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
11 Apr 2025, 14:50
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-754 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
05 Mar 2025, 14:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://supportportal.juniper.net/JSA83000 - Vendor Advisory | |
CPE | cpe:2.3:h:juniper:srx5000:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx1500:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx4600:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx480:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx650:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx300:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx3600:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx240:-:*:*:*:*:*:*:* cpe:2.3:o:juniper:junos:21.2:r3-s5:*:*:*:*:*:* cpe:2.3:h:juniper:srx550:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx1400:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx240m:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx100:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx4700:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:csrx:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx4200:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx5400:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx240h2:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx220:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx550_hm:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx380:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx4100:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx2300:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx960:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx240:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx5600:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx4300:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx110:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx320:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx340:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx3400:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx550m:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx1600:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx210:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:vsrx:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx4000:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx5800:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx345:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
First Time |
Juniper srx4000
Juniper mx960 Juniper srx5800 Juniper vsrx Juniper srx4600 Juniper srx340 Juniper srx320 Juniper srx210 Juniper srx650 Juniper srx345 Juniper srx4300 Juniper srx110 Juniper srx1600 Juniper srx550 Hm Juniper srx220 Juniper srx550m Juniper srx100 Juniper srx4100 Juniper srx3400 Juniper srx2300 Juniper srx380 Juniper srx1500 Juniper srx240m Juniper mx240 Juniper srx5400 Juniper csrx Juniper srx1400 Juniper srx240 Juniper srx550 Juniper srx5600 Juniper srx5000 Juniper srx300 Juniper srx4200 Juniper srx3600 Juniper srx240h2 Juniper srx4700 Juniper mx480 Juniper Juniper junos |
11 Jul 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-11 17:15
Updated : 2025-04-11 14:50
NVD link : CVE-2024-39540
Mitre link : CVE-2024-39540
JSON object : View
Products Affected
juniper
- srx4300
- srx380
- mx960
- junos
- srx1500
- srx3400
- srx2300
- srx240h2
- srx300
- srx220
- srx4000
- srx5000
- srx550_hm
- srx5600
- vsrx
- srx345
- srx5400
- srx210
- srx100
- srx1600
- mx240
- srx110
- csrx
- srx320
- srx4600
- mx480
- srx550m
- srx1400
- srx340
- srx550
- srx3600
- srx4100
- srx4200
- srx240
- srx650
- srx240m
- srx5800
- srx4700
CWE
CWE-754
Improper Check for Unusual or Exceptional Conditions