CVE-2024-39534 Information

Description

An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker to create sessions or send traffic to the device using the network and broadcast address of the subnet assigned to an interface. This is unintended and unexpected behavior and can allow an attacker to bypass certain compensating controls such as stateless firewall filters.

This issue affects Junos OS Evolved: 

All versions before 21.4R3-S8-EVO 
22.2-EVO before 22.2R3-S4-EVO 
22.3-EVO before 22.3R3-S4-EVO 
22.4-EVO before 22.4R3-S3-EVO 
23.2-EVO before 23.2R2-S1-EVO 
23.4-EVO before 23.4R1-S2-EVO 23.4R2-EVO.

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Reference

https://supportportal.juniper.net/JSA88105

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

5.4

Share on: