QID 44166
Date Published: 2024-01-24
QID 44166: Juniper Network Operating System (Junos OS) Exposure of Resource to Wrong Sphere Vulnerability (JSA75738)
Juniper Junos is the network operating system used in Juniper Networks hardware systems.
CVE-2024-21597: An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions.
To be exposed to this issue node-slicing must be configured:
[ chassis network-slices guest-network-functions ]
Affected Versions:
Junos OS versions earlier than 20.4R3-S9.
Junos OS 21.2 versions earlier than 21.2R3-S3.
Junos OS 21.4 versions earlier than 21.4R3-S5.
Junos OS 22.1 versions earlier than 22.1R3.
Junos OS 22.2 versions earlier than 22.2R3.
Junos OS 22.3 versions earlier than 22.3R2.
QID detection logic: (Authenticated)
This QID checks for vulnerable Junos OS versions.
Successful exploitation of this vulnerability may allows an unauthenticated, network-based attacker to bypass the intended access restrictions.
- JSA75738 -
supportportal.juniper.net/JSA75738
CVEs related to QID 44166
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JSA75738 |
|