← Back

CVE-2024-30378

nvd nist
Published: Apr 16, 2024Modified: Apr 11, 2025

JSON object

Loading...
6.9
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: sirt@juniper.net (Secondary)

Description

A Use After Free vulnerability in command processing of Juniper Networks Junos OS on MX Series allows a local, authenticated attacker to cause the broadband edge service manager daemon (bbe-smgd) to crash upon execution of specific CLI commands, creating a Denial of Service (DoS) condition.  The process crashes and restarts automatically. When specific CLI commands are executed, the bbe-smgd daemon attempts to write into an area of memory (mgd socket) that was already closed, causing the process to crash.  This process manages and controls the configuration of broadband subscriber sessions and services.  While the process is unavailable, additional subscribers will not be able to connect to the device, causing a temporary Denial of Service condition. This issue only occurs if Graceful Routing Engine Switchover (GRES) and Subscriber Management are enabled. This issue affects Junos OS: * All versions before 20.4R3-S5, * from 21.1 before 21.1R3-S4, * from 21.2 before 21.2R3-S3, * from 21.3 before 21.3R3-S5, * from 21.4 before 21.4R3-S5, * from 22.1 before 22.1R3, * from 22.2 before 22.2R3, * from 22.3 before 22.3R2;

Affected (74)

Products: Juniper: Junos
1 product
Junos
Configuration A
74 vulnerable · 20 platform
Vulnerable SoftwareAffected Versions
Juniper
Before 20.4
Version 20.4
Version 20.4 r1-s1
Version 20.4 r1
Version 20.4 r2-s1
Version 20.4 r2-s2
Version 20.4 r2
Version 20.4 r3-s1
Version 20.4 r3-s2
Version 20.4 r3-s3
Version 20.4 r3-s4
Version 20.4 r3
Version 21.1
Version 21.1 r1-s1
Version 21.1 r1
Version 21.1 r2-s1
Version 21.1 r2-s2
Version 21.1 r2
Version 21.1 r3-s1
Version 21.1 r3-s2
Version 21.1 r3-s3
Version 21.1 r3
Version 21.2
Version 21.2 r1-s1
Version 21.2 r1-s2
Version 21.2 r1
Version 21.2 r2-s1
Version 21.2 r2-s2
Version 21.2 r2
Version 21.2 r3-s1
Version 21.2 r3-s2
Version 21.2 r3
Version 21.3
Version 21.3 r1-s1
Version 21.3 r1-s2
Version 21.3 r1
Version 21.3 r2-s1
Version 21.3 r2-s2
Version 21.3 r2
Version 21.3 r3-s1
Version 21.3 r3-s2
Version 21.3 r3-s3
Version 21.3 r3-s4
Version 21.3 r3
Version 21.4
Version 21.4 r1-s1
Version 21.4 r1-s2
Version 21.4 r1
Version 21.4 r2-s1
Version 21.4 r2-s2
Version 21.4 r2
Version 21.4 r3-s1
Version 21.4 r3-s2
Version 21.4 r3-s3
Version 21.4 r3-s4
Version 21.4 r3
Version 22.1
Version 22.1 r1-s1
Version 22.1 r1-s2
Version 22.1 r1
Version 22.1 r2-s1
Version 22.1 r2-s2
Version 22.1 r2
Version 22.2
Version 22.2 r1-s1
Version 22.2 r1-s2
Version 22.2 r1
Version 22.2 r2-s1
Version 22.2 r2-s2
Version 22.2 r2
Version 22.3
Version 22.3 r1-s1
Version 22.3 r1-s2
Version 22.3 r1
Running on/withPlatform Versions
Juniper
Mx
All versions
Juniper
Mx10
All versions
Juniper
Mx10000
All versions
Juniper
Mx10003
All versions
Juniper
Mx10004
All versions
Juniper
Mx10008
All versions
Juniper
Mx10016
All versions
Juniper
Mx104
All versions
Juniper
Mx150
All versions
Juniper
Mx2008
All versions
Juniper
Mx2010
All versions
Juniper
Mx2020
All versions
Juniper
Mx204
All versions
Juniper
Mx240
All versions
Juniper
Mx304
All versions
Juniper
Mx40
All versions
Juniper
Mx480
All versions
Juniper
Mx5
All versions
Juniper
Mx80
All versions
Juniper
Mx960
All versions

References (4)

Timeline

No history available yet.