CVE-2024-39540
HIGH EPSS 38.5%
Published Jul 11, 20241y ago · Modified Jun 17, 20261w ago
8.7 CVSS 4.0
Published Jul 11, 2024 1y ago
Last Modified Jun 17, 2026 1w ago
Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on SRX Series, and MX Series with SPC3 allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affected device receives specific valid TCP traffic, the pfe crashes and restarts leading to a momentary but complete service outage. This issue affects Junos OS: 21.2 releases from 21.2R3-S5 before 21.2R3-S6. This issue does not affect earlier or later releases.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X
Threat Intelligence
EPSS Exploit Probability
38.5% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-754
Affected Products 38
| Vendor | Product | Version | Range |
|---|---|---|---|
| juniper | junos | 21.2 | any |
| juniper | csrx | * | any |
| juniper | mx240 | * | any |
| juniper | mx480 | * | any |
| juniper | mx960 | * | any |
| juniper | srx100 | * | any |
| juniper | srx110 | * | any |
| juniper | srx1400 | * | any |
| juniper | srx1500 | * | any |
| juniper | srx1600 | * | any |
| juniper | srx210 | * | any |
| juniper | srx220 | * | any |
| juniper | srx2300 | * | any |
| juniper | srx240 | * | any |
| juniper | srx240h2 | * | any |
| juniper | srx240m | * | any |
| juniper | srx300 | * | any |
| juniper | srx320 | * | any |
| juniper | srx340 | * | any |
| juniper | srx3400 | * | any |
| juniper | srx345 | * | any |
| juniper | srx3600 | * | any |
| juniper | srx380 | * | any |
| juniper | srx4000 | * | any |
| juniper | srx4100 | * | any |
| juniper | srx4200 | * | any |
| juniper | srx4300 | * | any |
| juniper | srx4600 | * | any |
| juniper | srx4700 | * | any |
| juniper | srx5000 | * | any |
| juniper | srx5400 | * | any |
| juniper | srx550 | * | any |
| juniper | srx550_hm | * | any |
| juniper | srx550m | * | any |
| juniper | srx5600 | * | any |
| juniper | srx5800 | * | any |
| juniper | srx650 | * | any |
| juniper | vsrx | * | any |
References 1
- supportportal.juniper.net https://supportportal.juniper.net/JSA83000
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.