CVE-2024-39519 is an Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX7000 Series devices. This flaw allows an unauthenticated, adjacent attacker to trigger a Denial-of-Service (DoS) by causing a traffic loop when multicast packets are sent from a dual-homed Customer Edge device to two Provider Edge devices configured with IRBs. The vulnerability affects Junos OS Evolved versions from 22.2R1-EVO up to, but not including, 22.4R2-EVO. Rated Medium severity with a CVSS score of 6.5, the attack vector is adjacent (AV:A) and requires low attack complexity (AC:L), with no privileges or user interaction needed. The primary impact is high availability loss (A:H) due to the DoS condition. Currently, there is no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 22.2, < 22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:*:*:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:22.4:-:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:22.4:r1:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:22.4:r1-s1:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:22.4:r1-s2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.