A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a local, low-privileged attacker to cause a Denial-of-Service (DoS).
When a specific command is executed, the pfe crashes. This will cause traffic forwarding to be interrupted until the system self-recovers. Repeated execution will create a sustained DoS condition.
 This issue only affects MX Series devices with Line cards MPC1-MPC9.
This issue affects:
Junos OS on MX Series: 
  *  All versions before 21.4R3-S9, 
  *  from 22.2 before 22.2R3-S5, 
  *  from 22.3 before 22.3R3-S4, 
  *  from 22.4 before 22.4R3-S2, 
  *  from 23.2 before 23.2R2-S1, 
  *  from 23.4 before 23.4R2.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://supportportal.juniper.net/ |     | 
History
                    Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Fri, 11 Oct 2024 15:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). When a specific command is executed, the pfe crashes. This will cause traffic forwarding to be interrupted until the system self-recovers. Repeated execution will create a sustained DoS condition. This issue only affects MX Series devices with Line cards MPC1-MPC9. This issue affects: Junos OS on MX Series: * All versions before 21.4R3-S9, * from 22.2 before 22.2R3-S5, * from 22.3 before 22.3R3-S4, * from 22.4 before 22.4R3-S2, * from 23.2 before 23.2R2-S1, * from 23.4 before 23.4R2. | |
| Title | Junos OS: MX Series: The PFE will crash on running specific command | |
| Weaknesses | CWE-476 | |
| References |  | |
| Metrics | cvssV3_1 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: juniper
Published: 2024-10-11T15:28:13.727Z
Updated: 2024-10-11T17:42:39.299Z
Reserved: 2024-09-25T15:26:52.609Z
Link: CVE-2024-47496
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-10-11T17:42:35.236Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2024-10-11T16:15:10.080
Modified: 2024-10-15T12:58:51.050
Link: CVE-2024-47496
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow