CVE-2024-30387 Details
Description
A Missing Synchronization vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on ACX5448 and ACX710 allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). If an interface flaps while the system gathers statistics on that interface, two processes simultaneously access a shared resource which leads to a PFE crash and restart. This issue affects Junos OS: * All versions before 20.4R3-S9, * 21.2 versions before 21.2R3-S5, * 21.3 versions before 21.3R3-S5, * 21.4 versions before 21.4R3-S4, * 22.1 versions before 22.1R3-S2, * 22.2 versions before 22.2R3-S2, * 22.3 versions before 22.3R2-S2, 22.3R3, * 22.4 versions before 22.4R2.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 12, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://supportportal.juniper.net/JSA79187 | CVE | Vendor Advisory |
| https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L | CVE | Issue Tracking |
| http://supportportal.juniper.net/JSA79187 | [email protected] | Vendor Advisory |
| https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L | [email protected] | Issue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-662 | Improper Synchronization | [email protected] |
| CWE-820 | Missing Synchronization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | < 20.4 20.4 - 20.4 r1 20.4 r1-s1 20.4 r2 20.4 r2-s1 20.4 r2-s2 20.4 r3 20.4 r3-s1 20.4 r3-s2 20.4 r3-s3 20.4 r3-s4 20.4 r3-s5 20.4 r3-s6 20.4 r3-s7 20.4 r3-s8 21.2 - 21.2 r1 21.2 r1-s1 21.2 r1-s2 21.2 r2 21.2 r2-s1 21.2 r2-s2 21.2 r3 21.2 r3-s1 21.2 r3-s2 21.2 r3-s3 21.2 r3-s4 21.3 - 21.3 r1 21.3 r1-s1 21.3 r1-s2 21.3 r2 21.3 r2-s1 21.3 r2-s2 21.3 r3 21.3 r3-s1 21.3 r3-s2 21.3 r3-s3 21.3 r3-s4 21.4 - 21.4 r1 21.4 r1-s1 21.4 r1-s2 21.4 r2 21.4 r2-s1 21.4 r2-s2 21.4 r3 21.4 r3-s1 21.4 r3-s2 21.4 r3-s3 22.1 - 22.1 r1 22.1 r1-s1 22.1 r1-s2 22.1 r2 22.1 r2-s1 22.1 r2-s2 22.1 r3 22.1 r3-s1 22.2 - 22.2 r1 22.2 r1-s1 22.2 r1-s2 22.2 r2 22.2 r2-s1 22.2 r2-s2 22.2 r3 22.2 r3-s1 22.3 - 22.3 r1 22.3 r1-s1 22.3 r1-s2 22.3 r2 22.3 r2-s1 22.4 - 22.4 r1 22.4 r1-s1 22.4 r1-s2 |
CPE
Remediation
| |
| juniper acx5448 | All versions |
CPE
Remediation
| |
| juniper acx710 | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Feb 6, 2025 | Initial Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 16, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 12, 2024 | New CVE Received | [email protected] |