An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an authenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS).When specific SNMP GET operations or specific low-priviledged CLI commands are executed, a GUID resource leak will occur, eventually leading to exhaustion and resulting in FPCs to hang. Affected FPCs need to be manually restarted to recover. GUID exhaustion will trigger a syslog message like one of the following: evo-pfemand[<pid>]: get_next_guid: Ran out of Guid Space ... evo-aftmand-zx[<pid>]: get_next_guid: Ran out of Guid Space ... The leak can be monitored by running the following command and taking note of the values in the rightmost column labeled Guids: user@host> show platform application-info allocations app evo-pfemand/evo-pfemand In case one or more of these values are constantly increasing the leak is happening. This issue affects Junos OS Evolved: * All versions before 21.4R3-S7-EVO, * 22.1 versions before 22.1R3-S6-EVO, * 22.2 versions before 22.2R3-EVO, * 22.3 versions before 22.3R3-EVO, * 22.4 versions before 22.4R2-EVO. Please note that this issue is similar to, but different from CVE-2024-47508 and CVE-2024-47509.
This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 6.5, indicating it can be exploited remotely over the network with relatively low complexity without requiring user interaction requiring only low-level privileges . The vulnerability impacts and availability (service disruption) for affected systems. Impacting 1 product from juniper organizations running these solutions should prioritize assessment and patching.
Reported in 2024, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.
2024-10-11T16:15:12.210
2026-01-23T20:03:56.497
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | juniper | junos_os_evolved | < 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.2 | Yes |
| Operating System | juniper | junos_os_evolved | 22.2 | Yes |
| Operating System | juniper | junos_os_evolved | 22.2 | Yes |
| Operating System | juniper | junos_os_evolved | 22.2 | Yes |
| Operating System | juniper | junos_os_evolved | 22.2 | Yes |
| Operating System | juniper | junos_os_evolved | 22.2 | Yes |
| Operating System | juniper | junos_os_evolved | 22.2 | Yes |
| Operating System | juniper | junos_os_evolved | 22.3 | Yes |
| Operating System | juniper | junos_os_evolved | 22.3 | Yes |
| Operating System | juniper | junos_os_evolved | 22.3 | Yes |
| Operating System | juniper | junos_os_evolved | 22.3 | Yes |
| Operating System | juniper | junos_os_evolved | 22.3 | Yes |
| Operating System | juniper | junos_os_evolved | 22.3 | Yes |
| Operating System | juniper | junos_os_evolved | 22.3 | Yes |
| Operating System | juniper | junos_os_evolved | 22.4 | Yes |
| Operating System | juniper | junos_os_evolved | 22.4 | Yes |
| Operating System | juniper | junos_os_evolved | 22.4 | Yes |
| Operating System | juniper | junos_os_evolved | 22.4 | Yes |
SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For juniper's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.