Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-47494 Details

Description

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to established sessions which generates counter changes picked up by the AgentD process during telemetry polling, to move the AgentD process into a state where AgentD attempts to reap an already destroyed sensor. This reaping attempt then leads to memory corruption causing the FPC to crash which is a Denial of Service (DoS). The FPC will recover automatically without user intervention after the crash. This issue affects Junos OS:  * All versions before 21.4R3-S9 * From 22.2 before 22.2R3-S5, * From 22.3 before 22.3R3-S4, * From 22.4 before 22.4R3-S3, * From 23.2 before 23.2R2-S2, * From 23.4 before 23.4R2. This issue does not affect Junos OS Evolved.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition[email protected]

Affected Products

ProductVersions
juniper junos
< 21.4
21.4 -
21.4 r1
21.4 r1-s1
21.4 r1-s2

CPE

  • cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:-:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r1-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r1-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r2-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r2-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r3:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r3-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r3-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r3-s3:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r3-s4:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r3-s5:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r3-s6:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r3-s7:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:21.4:r3-s8:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.2:-:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.2:r1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.2:r1-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.2:r1-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.2:r2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.2:r2-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.2:r2-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.2:r3:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.2:r3-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.2:r3-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.2:r3-s3:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.2:r3-s4:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.3:-:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.3:r1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.3:r1-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.3:r1-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.3:r2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.3:r2-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.3:r2-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.3:r3:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.3:r3-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.3:r3-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.3:r3-s3:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.4:-:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.4:r1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.4:r1-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.4:r1-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.4:r2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.4:r2-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.4:r2-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.4:r3:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.4:r3-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:22.4:r3-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.2:-:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.2:r1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.2:r1-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.2:r1-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.2:r2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.2:r2-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.4:-:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.4:r1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.4:r1-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.4:r1-s2:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-47494
NVD Published Date:
Oct 11, 2024
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2024-47494 Details - Not Deferred