CVE Vulnerabilities

CVE-2024-39534

Incorrect Comparison

Published: Oct 11, 2024 | Modified: Oct 11, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker to create sessions or send traffic to the device using the network and broadcast address of the subnet assigned to an interface. This is unintended and unexpected behavior and can allow an attacker to bypass certain compensating controls, such as stateless firewall filters.

This issue affects Junos OS Evolved: 

  • All versions before 21.4R3-S8-EVO, 
  • 22.2-EVO before 22.2R3-S4-EVO, 
  • 22.3-EVO before 22.3R3-S4-EVO, 
  • 22.4-EVO before 22.4R3-S3-EVO, 
  • 23.2-EVO before 23.2R2-S1-EVO, 
  • 23.4-EVO before 23.4R1-S2-EVO, 23.4R2-EVO.

Weakness

The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.

Extended Description

This Pillar covers several possibilities:

References