Product Affected

This issue affects all versions of Junos OS. Affected platforms: MX with LC9600, MPC10 or MPC11, and MX304.
Medium
6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

Problem

An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Network Junos OS on MX Series allows a network based attacker with low privileges to cause a denial of service.

If a scaled configuration for Source class usage (SCU) / destination class usage (DCU) (more than 10 route classes) is present and the SCU/DCU statistics are gathered by executing specific SNMP requests or CLI commands, a 'vmcore' for the RE kernel will be seen which leads to a device restart. Continued exploitation of this issue will lead to a sustained DoS.

This issue only affects MX Series devices with MPC10, MPC11 or LC9600, and MX304. No other MX Series devices are affected.

This issue affects Juniper Networks Junos OS:

  • All versions earlier than 20.4R3-S9;
  • 21.2 versions earlier than 21.2R3-S6;
  • 21.3 versions earlier than 21.3R3-S5;
  • 21.4 versions earlier than 21.4R3;
  • 22.1 versions earlier than 22.1R3;
  • 22.2 versions earlier than 22.2R2;
  • 22.3 versions earlier than 22.3R2.


To be exposed to this issue a scaled SCU/DCU configuration with more than 10 classes needs to be present on the device:

[ policy-options policy-statement <policy name> term <term name> then source-class/destination-class <scu/dcu-class name1> ]
...
[ policy-options policy-statement <policy name> term <term name> then source-class/destination-class <scu/dcu-class name11> ]
[ interface <interface> unit <unit#> family <family> accounting source-class-usage/destination-class-usage input/output ]


Juniper SIRT is not aware of any malicious exploitation of this vulnerability.


This issue was seen during production usage.


This issue has been assigned CVE-2024-21603.

Solution

The following software releases have been updated to resolve this specific issue: 20.4R3-S9, 21.2R3-S6, 21.3R3-S5, 21.4R3, 22.1R3, 22.2R2, 22.3R2, 22.4R1, and all subsequent releases.

This issue is being tracked as PR 1670797 which is visible on the Customer Support website.

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

There are no known workarounds for this issue.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2024-01-10: Initial Publication

Related Information

CVSS v4.0 Score: 7.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L )