2024-05-16 22:03:28 +00:00

63 lines
3.2 KiB
JSON

{
"id": "CVE-2024-30398",
"sourceIdentifier": "sirt@juniper.net",
"published": "2024-04-12T16:15:39.497",
"lastModified": "2024-05-16T21:16:09.590",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).\n\nWhen a high amount of specific traffic is received on a SRX4600 device, due to an error in internal packet handling, a consistent rise in CPU memory utilization occurs. This results in packet drops in the traffic and eventually the PFE crashes. A manual reboot of the PFE will be required to restore the device to original state.\n\nThis issue affects Junos OS:\u00a0\u00a0\n\n\n * 21.2 before\u00a021.2R3-S7,\n * 21.4 before 21.4R3-S6,\u00a0\n * 22.1 before 22.1R3-S5, \n * 22.2 before 22.2R3-S3,\n * 22.3 before 22.3R3-S2,\n * 22.4 before 22.4R3,\n\n * 23.2 before\u00a023.2R1-S2, 23.2R2."
},
{
"lang": "es",
"value": "Una restricci\u00f3n inadecuada de operaciones dentro de los l\u00edmites de una vulnerabilidad de b\u00fafer de memoria en el motor de reenv\u00edo de paquetes (PFE) de Juniper Networks Junos OS permite que un atacante no autenticado basado en la red provoque una denegaci\u00f3n de servicio (DoS). Cuando se recibe una gran cantidad de tr\u00e1fico espec\u00edfico en un dispositivo SRX4600, debido a un error en el manejo de paquetes internos, se produce un aumento constante en la utilizaci\u00f3n de la memoria de la CPU. Esto da como resultado ca\u00eddas de paquetes en el tr\u00e1fico y, finalmente, el PFE falla. Ser\u00e1 necesario reiniciar manualmente el PFE para restaurar el dispositivo a su estado original. Este problema afecta a Junos OS: 21.2 anterior a 21.2R3-S7, 21.4 anterior a 21.4R3-S6, 22.1 anterior a 22.1R3-S5, 22.2 anterior a 22.2R3-S3, 22.3 anterior a 22.3R3-S2, 22.4 anterior a 22.4R3, 23.2 anterior a 23.2R1 -S2, 23.2R2."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "sirt@juniper.net",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "sirt@juniper.net",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"references": [
{
"url": "https://supportportal.juniper.net/JSA79176",
"source": "sirt@juniper.net"
},
{
"url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L",
"source": "sirt@juniper.net"
}
]
}