An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions.
In an Abstracted Fabric (AF) scenario if routing-instances (RI) are configured, specific valid traffic destined to the device can bypass the configured lo0 firewall filters as it's received in the wrong RI context.
This issue affects Juniper Networks Junos OS on MX Series:
  *  All versions earlier than 20.4R3-S9;
  *  21.2 versions earlier than 21.2R3-S3;
  *  21.4 versions earlier than 21.4R3-S5;
  *  22.1 versions earlier than 22.1R3;
  *  22.2 versions earlier than 22.2R3;
  *  22.3 versions earlier than 22.3R2.
                
            References
                    | Link | Resource | 
|---|---|
| https://supportportal.juniper.net/JSA75738 | Vendor Advisory | 
| https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N | Third Party Advisory | 
| https://supportportal.juniper.net/JSA75738 | Vendor Advisory | 
| https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
Configuration 3 (hide)
| 
 | 
Configuration 4 (hide)
| 
 | 
Configuration 5 (hide)
| 
 | 
Configuration 6 (hide)
| 
 | 
History
                    21 Nov 2024, 08:54
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://supportportal.juniper.net/JSA75738 - Vendor Advisory | |
| References | () https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N - Third Party Advisory | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 5.3 | 
19 Jan 2024, 21:04
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-01-12 01:15
Updated : 2024-11-21 08:54
NVD link : CVE-2024-21597
Mitre link : CVE-2024-21597
CVE.ORG link : CVE-2024-21597
JSON object : View
Products Affected
                juniper
- junos
CWE
                
                    
                        
                        CWE-668
                        
            Exposure of Resource to Wrong Sphere
