CVE-2024-39518

7.5 HIGH

📋 TL;DR

A heap-based buffer overflow vulnerability in Juniper Networks Junos OS telemetry sensor process (sensord) causes memory leaks when specific telemetry subscriptions are active. This leads to gradual memory exhaustion and denial of service, requiring manual line card reboots. Affects MX240, MX480, and MX960 platforms with MPC10E running vulnerable Junos OS versions.

💻 Affected Systems

Products:
  • Juniper Networks MX240
  • Juniper Networks MX480
  • Juniper Networks MX960
Versions: Junos OS: from 21.2R3-S5 before 21.2R3-S7, from 21.4R3-S4 before 21.4R3-S6, from 22.2R3 before 22.2R3-S4, from 22.3R2 before 22.3R3-S2, from 22.4R1 before 22.4R3, from 23.2R1 before 23.2R2
Operating Systems: Junos OS
Default Config Vulnerable: ✅ No
Notes: Only vulnerable when telemetry subscription is active and on specific hardware (MPC10E line cards).

📦 What is this software?

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

⚠️ Risk & Real-World Impact

🔴

Worst Case

Complete device unresponsiveness requiring manual line card reboot, disrupting all network services on affected platforms.

🟠

Likely Case

Gradual performance degradation leading to service disruption over time, requiring intervention to restore functionality.

🟢

If Mitigated

Minimal impact if telemetry subscriptions are disabled or devices are patched before memory exhaustion occurs.

🌐 Internet-Facing: MEDIUM - Requires specific telemetry subscription configuration and affects only certain hardware platforms.
🏢 Internal Only: MEDIUM - Same technical impact but limited to internal network management plane access.

🎯 Exploit Status

Public PoC: ✅ No
Weaponized: UNKNOWN
Unauthenticated Exploit: ✅ No
Complexity: MEDIUM

Exploitation requires ability to configure telemetry subscriptions and affects specific hardware configurations.

🛠️ Fix & Mitigation

✅ Official Fix

Patch Version: Junos OS: 21.2R3-S7, 21.4R3-S6, 22.2R3-S4, 22.3R3-S2, 22.4R3, 23.2R2

Vendor Advisory: https://supportportal.juniper.net/JSA82982

Restart Required: Yes

Instructions:

1. Download appropriate patched version from Juniper support portal. 2. Backup configuration. 3. Install update following Juniper upgrade procedures. 4. Reboot affected devices.

🔧 Temporary Workarounds

Disable telemetry subscriptions

junos

Remove or disable Junos Telemetry Interface subscriptions to prevent memory leak trigger

configure
delete services analytics
commit

🧯 If You Can't Patch

  • Disable all telemetry subscriptions and monitor sensord memory usage regularly
  • Implement strict access controls to prevent unauthorized telemetry configuration changes

🔍 How to Verify

Check if Vulnerable:

Check Junos OS version and hardware platform: show version | match Junos, show chassis hardware | match MPC10E

Check Version:

show version | match Junos

Verify Fix Applied:

Verify Junos OS version is patched: show version | match Junos, and monitor sensord memory: show system info | match sensord

📡 Detection & Monitoring

Log Indicators:

  • Increasing sensord memory usage in system logs
  • Memory exhaustion warnings
  • Process crash reports for sensord

Network Indicators:

  • Gradual performance degradation
  • Increased response times
  • Telemetry data anomalies

SIEM Query:

process_name=sensord AND (memory_usage>threshold OR event_type=crash)

🔗 References

📤 Share & Export