You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
An Improper Handling of Exceptional Conditions vulnerability in the rpd-server of Juniper Networks Junos OS and Junos OS Evolved within cRPD allows an unauthenticated network-based attacker sending crafted TCP traffic to the routing engine (RE) to cause a CPU-based Denial of Service (DoS).
If specially crafted TCP traffic is received by the control plane, or a TCP session terminates unexpectedly, it will cause increased control plane CPU utilization by the rpd-server process.
While not explicitly required, the impact is more severe when RIB sharding is enabled.
Task accounting shows unexpected reads by the RPD Server jobs for shards:
user@junos> show task accounting detail
...
read:RPD Server.0.0.0.0+780.192.168.0.78+48886 TOT:00000003.00379787 MAX:00000000.00080516 RUNS: 233888\
read:RPD Server.0.0.0.0+780.192.168.0.78+49144 TOT:00000004.00007565 MAX:00000000.00080360 RUNS: 233888\
read:RPD Server.0.0.0.0+780.192.168.0.78+49694 TOT:00000003.00600584 MAX:00000000.00080463 RUNS: 233888\
read:RPD Server.0.0.0.0+780.192.168.0.78+50246 TOT:00000004.00346998 MAX:00000000.00080338 RUNS: 233888\
This issue affects:
Junos OS with cRPD:
* All versions before 21.2R3-S8,
* 21.4 before 21.4R3-S7,
* 22.1 before 22.1R3-S6,
* 22.2 before 22.2R3-S4,
* 22.3 before 22.3R3-S3,
* 22.4 before 22.4R3-S2,
* 23.2 before 23.2R2-S2,
* 24.2 before 24.2R2;
Junos OS Evolved with cRPD:
* All versions before 21.4R3-S7-EVO,
* 22.2 before 22.2R3-S4-EVO,
* 22.3 before 22.3R3-S3-EVO,
* 22.4 before 22.4R3-S2-EVO,
* 23.2 before 23.2R2-EVO.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
New CVE Received from Juniper Networks, Inc.10/11/2024 12:15:07 PM
Action
Type
Old Value
New Value
Added
Description
An Improper Handling of Exceptional Conditions vulnerability in the rpd-server of Juniper Networks Junos OS and Junos OS Evolved within cRPD allows an unauthenticated network-based attacker sending crafted TCP traffic to the routing engine (RE) to cause a CPU-based Denial of Service (DoS).
If specially crafted TCP traffic is received by the control plane, or a TCP session terminates unexpectedly, it will cause increased control plane CPU utilization by the rpd-server process.
While not explicitly required, the impact is more severe when RIB sharding is enabled.
Task accounting shows unexpected reads by the RPD Server jobs for shards:
user@junos> show task accounting detail
...
read:RPD Server.0.0.0.0+780.192.168.0.78+48886 TOT:00000003.00379787 MAX:00000000.00080516 RUNS: 233888\
read:RPD Server.0.0.0.0+780.192.168.0.78+49144 TOT:00000004.00007565 MAX:00000000.00080360 RUNS: 233888\
read:RPD Server.0.0.0.0+780.192.168.0.78+49694 TOT:00000003.00600584 MAX:00000000.00080463 RUNS: 233888\
read:RPD Server.0.0.0.0+780.192.168.0.78+50246 TOT:00000004.00346998 MAX:00000000.00080338 RUNS: 233888\
This issue affects:
Junos OS with cRPD:
* All versions before 21.2R3-S8,
* 21.4 before 21.4R3-S7,
* 22.1 before 22.1R3-S6,
* 22.2 before 22.2R3-S4,
* 22.3 before 22.3R3-S3,
* 22.4 before 22.4R3-S2,
* 23.2 before 23.2R2-S2,
* 24.2 before 24.2R2;
Junos OS Evolved with cRPD:
* All versions before 21.4R3-S7-EVO,
* 22.2 before 22.2R3-S4-EVO,
* 22.3 before 22.3R3-S3-EVO,
* 22.4 before 22.4R3-S2-EVO,
* 23.2 before 23.2R2-EVO.
Added
CVSS V4.0
Juniper Networks, Inc. CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:X
Added
CVSS V3.1
Juniper Networks, Inc. AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Added
CWE
Juniper Networks, Inc. CWE-755
Added
Reference
Juniper Networks, Inc. https://supportportal.juniper.net/JSA88108 [No types assigned]
Quick Info
CVE Dictionary Entry: CVE-2024-39547 NVD
Published Date: 10/11/2024 NVD
Last Modified: 01/26/2026
Source: Juniper Networks, Inc.