An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device.



Due to a wrong initialization, specific processes which should only be able to communicate internally within the device can be reached over the network via open ports.




This issue affects Junos OS Evolved on ACX 7000 Series:



* All versions before 21.4R3-S7-EVO,
* 22.2-EVO

versions

before 22.2R3-S4-EVO,
* 22.3-EVO versions before 22.3R3-S3-EVO,
* 22.4-EVO versions before 22.4R3-S2-EVO,
* 23.2-EVO versions before 23.2R2-EVO,
* 23.4-EVO versions before 23.4R1-S1-EVO, 23.4R2-EVO.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-38063 An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due to a wrong initialization, specific processes which should only be able to communicate internally within the device can be reached over the network via open ports. This issue affects Junos OS Evolved on ACX 7000 Series: * All versions before 21.4R3-S7-EVO, * 22.2-EVO versions before 22.2R3-S4-EVO, * 22.3-EVO versions before 22.3R3-S3-EVO, * 22.4-EVO versions before 22.4R3-S2-EVO, * 23.2-EVO versions before 23.2R2-EVO, * 23.4-EVO versions before 23.4R1-S1-EVO, 23.4R2-EVO.
Fixes

Solution

The following software releases have been updated to resolve this specific issue: 21.4R3-S7-EVO, 22.2R3-S4-EVO, 22.3R3-S3-EVO, 22.4R3-S2-EVO, 23.2R2-EVO, 23.4R1-S1-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases.


Workaround

There are no known workarounds for this issue.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2024-08-02T04:26:15.676Z

Reserved: 2024-06-25T15:12:53.241Z

Link: CVE-2024-39537

cve-icon Vulnrichment

Updated: 2024-07-11T18:56:59.079Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-11T17:15:11.843

Modified: 2024-11-21T09:27:57.533

Link: CVE-2024-39537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.