An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices allows an unauthenticated, network based attacker sending specific transit protocol traffic to cause a partial Denial of Service (DoS) to downstream devices.
Receipt of specific transit protocol packets is incorrectly processed by the Routing Engine (RE), filling up the DDoS protection queue which is shared between routing protocols. This influx of transit protocol packets causes DDoS protection violations, resulting in protocol flaps which can affect connectivity to networking devices.
This issue affects both IPv4 and IPv6. This issue does not require any specific routing protocol to be configured or enabled.
The following commands can be used to monitor the DDoS protection queue:
       labuser@re0> show evo-pfemand host pkt-stats
    labuser@re0> show host-path ddos all-policers
This issue affects Junos OS Evolved: 
  *  All versions before 21.4R3-S8-EVO, 
  *  from 22.2 before 22.2R3-S4-EVO, 
  *  from 22.3 before 22.3R3-S4-EVO, 
  *  from 22.4 before 22.4R3-S3-EVO, 
  *  from 23.2 before 23.2R2-EVO, 
  *  from 23.4 before 23.4R1-S1-EVO, 23.4R2-EVO, 
  *  from 24.2 before 24.2R2-EVO.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://supportportal.juniper.net/ |     | 
History
                    Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Juniper Juniper junos Evolved | |
| CPEs | cpe:2.3:o:juniper:junos_evolved:*:*:*:*:*:*:*:* | |
| Vendors & Products | Juniper Juniper junos Evolved | |
| Metrics | ssvc 
 | 
Fri, 11 Oct 2024 15:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices allows an unauthenticated, network based attacker sending specific transit protocol traffic to cause a partial Denial of Service (DoS) to downstream devices. Receipt of specific transit protocol packets is incorrectly processed by the Routing Engine (RE), filling up the DDoS protection queue which is shared between routing protocols. This influx of transit protocol packets causes DDoS protection violations, resulting in protocol flaps which can affect connectivity to networking devices. This issue affects both IPv4 and IPv6. This issue does not require any specific routing protocol to be configured or enabled. The following commands can be used to monitor the DDoS protection queue: labuser@re0> show evo-pfemand host pkt-stats labuser@re0> show host-path ddos all-policers This issue affects Junos OS Evolved: * All versions before 21.4R3-S8-EVO, * from 22.2 before 22.2R3-S4-EVO, * from 22.3 before 22.3R3-S4-EVO, * from 22.4 before 22.4R3-S3-EVO, * from 23.2 before 23.2R2-EVO, * from 23.4 before 23.4R1-S1-EVO, 23.4R2-EVO, * from 24.2 before 24.2R2-EVO. | |
| Title | Junos OS Evolved: ACX Series: Receipt of specific transit protocol packets is incorrectly processed by the RE | |
| Weaknesses | CWE-755 | |
| References |  | |
| Metrics | cvssV3_1 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: juniper
Published: 2024-10-11T15:22:00.413Z
Updated: 2024-10-11T18:00:33.801Z
Reserved: 2024-09-25T15:26:52.608Z
Link: CVE-2024-47489
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-10-11T18:00:26.125Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2024-10-11T16:15:08.533
Modified: 2024-11-21T09:39:49.923
Link: CVE-2024-47489
 Redhat
                        Redhat
                    No data.