CVE-2024-39540

HIGH EPSS 38.5%
Published Jul 11, 20241y ago · Modified Jun 17, 20261w ago
8.7 CVSS 4.0
High
Find Similar
Published Jul 11, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on SRX Series, and MX Series with SPC3 allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affected device receives specific valid TCP traffic, the pfe crashes and restarts leading to a momentary but complete service outage. This issue affects Junos OS: 21.2 releases from 21.2R3-S5 before 21.2R3-S6. This issue does not affect earlier or later releases.

CVSS Details

Base Score
8.7
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
38.5% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-754

Affected Products 38

VendorProductVersionRange
juniperjunos21.2any
junipercsrx*any
junipermx240*any
junipermx480*any
junipermx960*any
junipersrx100*any
junipersrx110*any
junipersrx1400*any
junipersrx1500*any
junipersrx1600*any
junipersrx210*any
junipersrx220*any
junipersrx2300*any
junipersrx240*any
junipersrx240h2*any
junipersrx240m*any
junipersrx300*any
junipersrx320*any
junipersrx340*any
junipersrx3400*any
junipersrx345*any
junipersrx3600*any
junipersrx380*any
junipersrx4000*any
junipersrx4100*any
junipersrx4200*any
junipersrx4300*any
junipersrx4600*any
junipersrx4700*any
junipersrx5000*any
junipersrx5400*any
junipersrx550*any
junipersrx550_hm*any
junipersrx550m*any
junipersrx5600*any
junipersrx5800*any
junipersrx650*any
junipervsrx*any

References 1

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.