CVE-2024-47497

HIGH EPSS 43.1%
Published Oct 11, 20241y ago · Modified Jun 17, 20261w ago
8.7 CVSS 4.0
High
Find Similar
Published Oct 11, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series, QFX Series, MX Series and EX Series allows an unauthenticated, network-based attacker to cause Denial-of-Service (DoS). An attacker can send specific HTTPS connection requests to the device, triggering the creation of processes that are not properly terminated. Over time, this leads to resource exhaustion, ultimately causing the device to crash and restart. The following command can be used to monitor the resource usage: user@host> show system processes extensive | match mgd | count This issue affects Junos OS on SRX Series and EX Series: All versions before 21.4R3-S7, from 22.2 before 22.2R3-S4, from 22.3 before 22.3R3-S3, from 22.4 before 22.4R3-S2, from 23.2 before 23.2R2-S1, from 23.4 before 23.4R1-S2, 23.4R2.

CVSS Details

Base Score
8.7
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:A/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
43.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-400 Uncontrolled Resource Consumption Resource Mgmt

Affected Products 108

VendorProductVersionRange
juniperjunos* <21.4
juniperjunos21.4any
juniperjunos21.4any
juniperjunos21.4any
juniperjunos21.4any
juniperjunos21.4any
juniperjunos21.4any
juniperjunos21.4any
juniperjunos21.4any
juniperjunos21.4any
juniperjunos21.4any
juniperjunos21.4any
juniperjunos21.4any
juniperjunos21.4any
juniperjunos21.4any
juniperjunos22.2any
juniperjunos22.2any
juniperjunos22.2any
juniperjunos22.2any
juniperjunos22.2any
juniperjunos22.2any
juniperjunos22.2any
juniperjunos22.2any
juniperjunos22.2any
juniperjunos22.2any
juniperjunos22.2any
juniperjunos22.3any
juniperjunos22.3any
juniperjunos22.3any
juniperjunos22.3any
juniperjunos22.3any
juniperjunos22.3any
juniperjunos22.3any
juniperjunos22.3any
juniperjunos22.3any
juniperjunos22.3any
juniperjunos22.4any
juniperjunos22.4any
juniperjunos22.4any
juniperjunos22.4any
juniperjunos22.4any
juniperjunos22.4any
juniperjunos22.4any
juniperjunos22.4any
juniperjunos22.4any
juniperjunos23.2any
juniperjunos23.2any
juniperjunos23.2any
juniperjunos23.2any
juniperjunos23.2any
juniperjunos23.4any
juniperjunos23.4any
juniperjunos23.4any
juniperjunos23.4any
juniperex2300*any
juniperex2300-c*any
juniperex3400*any
juniperex4000*any
juniperex4100*any
juniperex4100-f*any
juniperex4100-h*any
juniperex4300*any
juniperex4400*any
juniperex4600*any
juniperex4650*any
juniperex9204*any
juniperex9208*any
juniperex9214*any
junipermx10004*any
junipermx10008*any
junipermx2008*any
junipermx2010*any
junipermx2020*any
junipermx204*any
junipermx240*any
junipermx304*any
junipermx480*any
junipermx960*any
juniperqfx10002*any
juniperqfx10008*any
juniperqfx10016*any
juniperqfx5110*any
juniperqfx5120*any
juniperqfx5130*any
juniperqfx5200*any
juniperqfx5210*any
juniperqfx5220*any
juniperqfx5230-64cd*any
juniperqfx5240*any
juniperqfx5241*any
juniperqfx5700*any
junipersrx1500*any
junipersrx1600*any
junipersrx2300*any
junipersrx300*any
junipersrx320*any
junipersrx340*any
junipersrx345*any
junipersrx380*any
junipersrx4100*any
junipersrx4120*any
junipersrx4200*any
junipersrx4300*any
junipersrx4600*any
junipersrx4700*any
junipersrx5400*any
junipersrx5600*any
junipersrx5800*any

References 1

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.