A Deadlock vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).
When a large amount of traffic is processed by ATP Cloud inspection, a deadlock can occur which will result in a PFE crash and restart. Whether the crash occurs, depends on system internal timing that is outside the attackers control.
This issue affects Junos OS on SRX Series:
  *  All versions before 21.3R3-S1,
  *  21.4 versions before 21.4R3,
  *  22.1 versions before 22.1R2,
  *  22.2 versions before 22.2R1-S2, 22.2R2.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://supportportal.juniper.net/JSA88137 | 
                     | 
            
History
                    Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Fri, 11 Oct 2024 15:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A Deadlock vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When a large amount of traffic is processed by ATP Cloud inspection, a deadlock can occur which will result in a PFE crash and restart. Whether the crash occurs, depends on system internal timing that is outside the attackers control. This issue affects Junos OS on SRX Series: * All versions before 21.3R3-S1, * 21.4 versions before 21.4R3, * 22.1 versions before 22.1R2, * 22.2 versions before 22.2R1-S2, 22.2R2. | |
| Title | Junos OS: SRX Series: A large amount of traffic being processed by ATP Cloud can lead to a PFE crash | |
| Weaknesses | CWE-833 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
 
  | 
Status: PUBLISHED
Assigner: juniper
Published:
Updated: 2024-10-11T17:15:46.190Z
Reserved: 2024-09-25T15:26:52.610Z
Link: CVE-2024-47506
Updated: 2024-10-11T17:15:35.947Z
Status : Awaiting Analysis
Published: 2024-10-11T16:15:12.450
Modified: 2024-10-15T12:58:51.050
Link: CVE-2024-47506
No data.