Does the vulnerability CVE-2024-47494 impact SRX?
What is the condition if there is an impact?
What would be the workaround?
The FPC will crash and recover automatically without user intervention.
The following minimal configuration is required for exposure:
[services analytics]
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to established sessions which generates counter changes picked up by the AgentD process during telemetry polling, to move the AgentD process into a state where AgentD attempts to reap an already destroyed sensor. This reaping attempt then leads to memory corruption causing the FPC to crash which is a Denial of Service (DoS).
The vulnerability CVE-2024-47494 states that the attacker who is already influencing the current sessions indirectly corrupts memory.
The AgentD process will be running by default, and it will be retrieving counters Time-of-check Time-of-use values for it's evaluation.
The attacker influences the current session by generating traffic that generates these counters which will be picked up by AgentD process and evaluated.
The wrong counter values will make AgentD attempt to reap an already destroyed sensor causing memory corruption.
The attacker does not require to log-in to the device to influence the session counters. He will need to generate specific traffic that affects the counters that AgentD uses.
Refer to the JSA article - https://supportportal.juniper.net/s/article/2024-10-Security-Bulletin-Junos-OS-Due-to-a-race-condition-AgentD-process-causes-a-memory-corruption-and-FPC-reset-CVE-2024-47494
The following software releases have been updated to resolve this specific issue:
Junos OS: 21.4R3-S9, 22.2R3-S5, 22.3R3-S4, 22.4R3-S3, 23.2R2-S2, 23.4R2, 24.2R1, and all subsequent releases.
This issue is being tracked as 1769294 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).