Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-47496


A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). When a specific command is executed, the pfe crashes. This will cause traffic forwarding to be interrupted until the system self-recovers. Repeated execution will create a sustained DoS condition. This issue only affects MX Series devices with Line cards MPC1-MPC9. This issue affects: Junos OS on MX Series: * All versions before 21.4R3-S9, * from 22.2 before 22.2R3-S5,  * from 22.3 before 22.3R3-S4, * from 22.4 before 22.4R3-S2, * from 23.2 before 23.2R2-S1, * from 23.4 before 23.4R2.


Security Impact Summary

This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 5.5, requiring local system access to exploit with relatively low complexity without requiring user interaction requiring only low-level privileges . The vulnerability impacts and availability (service disruption) for affected systems. Impacting 33 products from juniper, from juniper, from juniper and 30 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2024, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2024-10-11T16:15:10.080

Last Modified

2026-01-26T18:19:15.840

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System juniper junos < 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 21.4 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.2 Yes
Operating System juniper junos 22.3 Yes
Operating System juniper junos 22.3 Yes
Operating System juniper junos 22.3 Yes
Operating System juniper junos 22.3 Yes
Operating System juniper junos 22.3 Yes
Operating System juniper junos 22.3 Yes
Operating System juniper junos 22.3 Yes
Operating System juniper junos 22.3 Yes
Operating System juniper junos 22.3 Yes
Operating System juniper junos 22.3 Yes
Operating System juniper junos 22.3 Yes
Operating System juniper junos 22.4 Yes
Operating System juniper junos 22.4 Yes
Operating System juniper junos 22.4 Yes
Operating System juniper junos 22.4 Yes
Operating System juniper junos 22.4 Yes
Operating System juniper junos 22.4 Yes
Operating System juniper junos 22.4 Yes
Operating System juniper junos 22.4 Yes
Operating System juniper junos 22.4 Yes
Operating System juniper junos 23.2 Yes
Operating System juniper junos 23.2 Yes
Operating System juniper junos 23.2 Yes
Operating System juniper junos 23.2 Yes
Operating System juniper junos 23.2 Yes
Operating System juniper junos 23.4 Yes
Operating System juniper junos 23.4 Yes
Operating System juniper junos 23.4 Yes
Operating System juniper junos 23.4 Yes
Hardware juniper 2x100ge_\+_4x10ge_mpc5e - No
Hardware juniper 2x100ge_\+_4x10ge_mpc5eq - No
Hardware juniper 2x100ge_\+_8x10ge_mpc4e - No
Hardware juniper 32x10ge_mpc4e - No
Hardware juniper 6x40ge_\+_24x10ge_mpc5e - No
Hardware juniper 6x40ge_\+_24x10ge_mpc5eq - No
Hardware juniper mpc1 - No
Hardware juniper mpc1_q - No
Hardware juniper mpc1e - No
Hardware juniper mpc1e_q - No
Hardware juniper mpc2 - No
Hardware juniper mpc2_eq - No
Hardware juniper mpc2_q - No
Hardware juniper mpc2e - No
Hardware juniper mpc2e_eq - No
Hardware juniper mpc2e_ng - No
Hardware juniper mpc2e_ng_q - No
Hardware juniper mpc2e_p - No
Hardware juniper mpc2e_q - No
Hardware juniper mpc3e - No
Hardware juniper mpc3e-3d-ng - No
Hardware juniper mpc3e-3d-ng-q - No
Hardware juniper mpc6e - No
Hardware juniper mpc7e-10g - No
Hardware juniper mpc7e-mrate - No
Hardware juniper mpc8e - No
Hardware juniper mpc9e - No
Hardware juniper mx2008 - No
Hardware juniper mx2010 - No
Hardware juniper mx240 - No
Hardware juniper mx480 - No
Hardware juniper mx960 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For juniper's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.