Vulnerability Description
An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows an unauthenticated, network-based attacker to cause an integrity impact to networks downstream of the vulnerable device. When an output firewall filter is applied to an interface it doesn't recognize matching packets but permits any traffic. This issue affects Junos OS 21.4 releases from 21.4R1 earlier than 21.4R3-S6. This issue does not affect Junos OS releases earlier than 21.4R1.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | 21.4 |
| Juniper | Ex4300 | - |
| Juniper | Ex4300-24P | - |
| Juniper | Ex4300-24P-S | - |
| Juniper | Ex4300-24T | - |
| Juniper | Ex4300-24T-S | - |
| Juniper | Ex4300-32F | - |
| Juniper | Ex4300-32F-Dc | - |
| Juniper | Ex4300-32F-S | - |
| Juniper | Ex4300-48Mp | - |
| Juniper | Ex4300-48Mp-S | - |
| Juniper | Ex4300-48P | - |
| Juniper | Ex4300-48P-S | - |
| Juniper | Ex4300-48T | - |
| Juniper | Ex4300-48T-Afi | - |
| Juniper | Ex4300-48T-Dc | - |
| Juniper | Ex4300-48T-Dc-Afi | - |
| Juniper | Ex4300-48T-S | - |
Related Weaknesses (CWE)
References
- http://supportportal.juniper.net/JSA79185Vendor Advisory
- https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:NIssue Tracking
- http://supportportal.juniper.net/JSA79185Vendor Advisory
- https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:NIssue Tracking
FAQ
What is CVE-2024-30389?
CVE-2024-30389 is a vulnerability with a CVSS score of 5.8 (MEDIUM). An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows an unauthenticated, network-based attacker to cause an integrity im...
How severe is CVE-2024-30389?
CVE-2024-30389 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-30389?
Check the references section above for vendor advisories and patch information. Affected products include: Juniper Junos, Juniper Ex4300, Juniper Ex4300-24P, Juniper Ex4300-24P-S, Juniper Ex4300-24T.