U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-39561

Change History

New CVE Received by NIST 7/10/2024 7:15:13 PM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
Juniper Networks, Inc. AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Added CVSS V4.0

								
							
							
						
Juniper Networks, Inc. CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Added CWE

								
							
							
						
Juniper Networks, Inc. CWE-754
Added Description

								
							
							
						
An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on 

SRX4600 and SRX5000 Series

 allows an attacker to send TCP packets with 

SYN/FIN or SYN/RST

 flags, bypassing the expected blocking of these packets.

A TCP packet with SYN/FIN or SYN/RST should be dropped in flowd. However, when no-syn-check and Express Path are enabled, these TCP packets are unexpectedly transferred to the downstream network.

This issue affects Junos OS on SRX4600 and SRX5000 Series: 


  *  All versions before 21.2R3-S8, 
  *  from 21.4 before 21.4R3-S7, 
  *  from 22.1 before 22.1R3-S6, 
  *  from 22.2 before 22.2R3-S4, 
  *  from 22.3 before 22.3R3-S3, 
  *  from 22.4 before 22.4R3-S2, 
  *  from 23.2 before 23.2R2, 
  *  from 23.4 before 23.4R1-S1, 23.4R2.
Added Reference

								
							
							
						
Juniper Networks, Inc. https://supportportal.juniper.net/JSA83021 [No types assigned]