CVE-2024-21597

MEDIUM

Juniper Junos - Exposure to Wrong Actor

Title source: rule
STIX 2.1

Description

An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions. In an Abstracted Fabric (AF) scenario if routing-instances (RI) are configured, specific valid traffic destined to the device can bypass the configured lo0 firewall filters as it's received in the wrong RI context. This issue affects Juniper Networks Junos OS on MX Series: * All versions earlier than 20.4R3-S9; * 21.2 versions earlier than 21.2R3-S3; * 21.4 versions earlier than 21.4R3-S5; * 22.1 versions earlier than 22.1R3; * 22.2 versions earlier than 22.2R3; * 22.3 versions earlier than 22.3R2.

Scores

CVSS v3 5.3
EPSS 0.0003
EPSS Percentile 10.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-668
Status published
Products (5)
juniper/junos 20.4 (15 CPE variants)
juniper/junos 21.2 (10 CPE variants)
juniper/junos 21.4 (12 CPE variants)
juniper/junos 22.1 (7 CPE variants)
juniper/junos 22.2 (6 CPE variants)
Published Jan 12, 2024
Tracked Since Feb 18, 2026