QID 44154
Date Published: 2024-01-24
QID 44154: Juniper Network Operating System (Junos OS) Improper Neutralization of Equivalent Special Elements vulnerability (JSA75741)
Junos OS is the network operating system developed by Juniper Networks, designed for routing, switching, and security applications in their networking devices.
CVE-2024-21600: An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows a unauthenticated, adjacent attacker to cause a Denial of Service (DoS).
Affected Versions:
Junos OS versions earlier than 20.4R3-S8.
Junos OS 21.1 versions earlier than 21.1R3-S4.
Junos OS 21.2 versions earlier than 21.2R3-S6.
Junos OS 21.3 versions earlier than 21.3R3-S3.
Junos OS 21.4 versions earlier than 21.4R3-S5.
Junos OS 22.1 versions earlier than 22.1R2-S2, 22.1R3.
Junos OS 22.2 versions earlier than 22.2R2-S1, 22.2R3.
QID detection logic: (Authenticated)
It checks for vulnerable Junos OS version.
Repeated execution by the attacker will create a sustained Denial of Service (DoS) condition.
Workaround:
The issue can be prevented by configuring a limit for reject packets via:
system ddos-protection protocols reject aggregate bandwidth 20.
- JSA75741 -
supportportal.juniper.net/JSA75741
CVEs related to QID 44154
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA75741 |
|