An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network based, attacker to cause the RPD process to crash leading to a Denial of Service (DoS).When a malformed BGP path attributes packet is received over an established BGP session, RPD crashes and restarts.Continuous receipt of the malformed BGP path attributes messages will create a sustained Denial of Service (DoS) condition for impacted devices.This issue affects:Junos OS:
The following software releases have been updated to resolve this specific issue:Junos OS: 21.2R3-S8, 21.4R3-S8, 22.2R3-S5*, 22.3R3-S4*, 22.4R3-S4, 23.2R2-S1, 23.4R1-S2, 23.4R2, 24.2R1, and all subsequent releases.Junos OS Evolved: 21.2R3-S8-EVO, 21.4R3-S8-EVO, 22.2R3-S5-EVO*, 22.3R3-S4-EVO*, 22.4R3-S4-EVO, 23.2R2-S1-EVO, 23.4R1-S2-EVO, 23.4R2-EVO, 24.2R1-EVO and all subsequent releases. *Future release
This issue is being tracked as 1778879 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
2024-07-10: Initial Publication 2024-07-12: Added 21.4R3-S8 to list of fixed Junos OS releases 2024-09-13: Minor formatting change to CVSS field 2024-09-19: Added fixed versions and updated tittle/description 2024-10-02: Fixed typo and removed 24.2R2 and 24.2R2-EVO in "This issue affects.." Junos OS and Junos OS Evolved version table respectively.2025-02-05: An issue found in 22.4R3-S3 was fixed in 22.4R3-S4 and added in the new CVE-2024-39564.
Juniper SIRT would like to acknowledge and thank Craig Dods from Meta for responsibly reporting this vulnerability.