Threat Advisory

Multiple Juniper Networks Flaw Let Attackers Delete Files

Threat: Vulnerability
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A vulnerability, identified as CVE-2024-30409, has been discovered in Juniper Networks Junos OS and Junos OS Evolved, impacting versions from 22.1 before 22.1R1-S2 and 22.1R2 respectively. This vulnerability arises in the telemetry processing, allowing a network-based attacker with authentication privileges to trigger a crash in the forwarding information base telemetry daemon (fibtd), resulting in a limited Denial of Service (DoS) scenario. The issue occurs specifically when telemetry subscription is active and Fib-streaming is enabled.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A vulnerability, identified as CVE-2024-30409, has been discovered in Juniper Networks Junos OS and Junos OS Evolved, impacting versions from 22.1 before 22.1R1-S2 and 22.1R2 respectively. This vulnerability arises in the telemetry processing, allowing a network-based attacker with authentication privileges to trigger a crash in the forwarding information base telemetry daemon (fibtd), resulting in a limited Denial of Service (DoS) scenario. The issue occurs specifically when telemetry subscription is active and Fib-streaming is enabled.[emaillocker id="1283"]

 

RECOMMENDATION:

  • We strongly recommend you update Junos OS to versions 22.1R1-S2, 22.1R2, 22.2R1, 22.2R2, 22.3R1, 22.4R1 and Junos OS Evolved to versions 22.1R1-S2-EVO, 22.1R2-EVO, 22.2R1-EVO, 22.2R2-EVO, 22.3R1-EVO, 22.4R1-EVO.

 

REFERENCES:

The following reports contain further technical details: https://cybersecuritynews.com/juniper-networks-flaws/

[/emaillocker]
crossmenu