CVE-2024-39535

MEDIUM

Juniper Junos OS Evolved 22.4R2-S1 and 22.4R2-S2 - Unauthenticated Denial of Service in Packet Forwarding Engine

Title source: llm
STIX 2.1

Description

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). When a device has a Layer 3 or an IRB interface configured in a VPLS instance and specific traffic is received, the evo-pfemand processes crashes which causes a service outage for the respective FPC until the system is recovered manually. This issue only affects Junos OS Evolved 22.4R2-S1 and 22.4R2-S2 releases and is fixed in 22.4R3. No other releases are affected.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
https://supportportal.juniper.net/JSA82995

Scores

CVSS v3 6.5
EPSS 0.0033
EPSS Percentile 24.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (1)
juniper/junos_os_evolved 22.4 r2-s1 (2 CPE variants)
Published Jul 11, 2024
Tracked Since Feb 18, 2026