CVE-2024-21595 Details
Description
An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If an attacker sends high rate of specific ICMP traffic to a device with VXLAN configured, this causes a deadlock of the PFE and results in the device becoming unresponsive. A manual restart will be required to recover the device. This issue only affects EX4100, EX4400, EX4600, QFX5000 Series devices. This issue affects: Juniper Networks Junos OS * 21.4R3 versions earlier than 21.4R3-S4; * 22.1R3 versions earlier than 22.1R3-S3; * 22.2R2 versions earlier than 22.2R3-S1; * 22.3 versions earlier than 22.3R2-S2, 22.3R3; * 22.4 versions earlier than 22.4R2; * 23.1 versions earlier than 23.1R2.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://advisory.juniper.net/JSA75734 | CVE | Vendor Advisory |
| https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N | CVE | Third Party Advisory |
| https://advisory.juniper.net/JSA75734 | [email protected] | Vendor Advisory |
| https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-1286 | Improper Validation of Syntactic Correctness of Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | 21.4 r3 21.4 r3-s1 21.4 r3-s2 21.4 r3-s3 22.1 r3 22.1 r3-s1 22.1 r3-s2 22.2 r2 22.2 r2-s1 22.2 r2-s2 22.2 r3 22.3 - 22.3 r1 22.3 r1-s1 22.3 r1-s2 22.3 r2 22.3 r2-s1 22.4 - 22.4 r1 22.4 r1-s1 22.4 r1-s2 23.1 r1 |
CPE
Remediation
| |
| juniper ex4100 | All versions |
CPE
Remediation
| |
| juniper ex4400 | All versions |
CPE
Remediation
| |
| juniper ex4600 | All versions |
CPE
Remediation
| |
| juniper qfx5100 | All versions |
CPE
Remediation
| |
| juniper qfx5100-96s | All versions |
CPE
Remediation
| |
| juniper qfx5110 | All versions |
CPE
Remediation
| |
| juniper qfx5120 | All versions |
CPE
Remediation
| |
| juniper qfx5130 | All versions |
CPE
Remediation
| |
| juniper qfx5200 | All versions |
CPE
Remediation
| |
| juniper qfx5200-32c | All versions |
CPE
Remediation
| |
| juniper qfx5200-48y | All versions |
CPE
Remediation
| |
| juniper qfx5210 | All versions |
CPE
Remediation
| |
| juniper qfx5210-64c | All versions |
CPE
Remediation
| |
| juniper qfx5220 | All versions |
CPE
Remediation
| |
| juniper qfx5700 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 18, 2024 | Initial Analysis | [email protected] |
| Jan 12, 2024 | New CVE Received | [email protected] |