CVE-2024-47506

5.9 MEDIUM

📋 TL;DR

A deadlock vulnerability in Juniper SRX Series packet forwarding engine allows unauthenticated network attackers to cause denial of service by sending large amounts of traffic through ATP Cloud inspection. This affects Junos OS on SRX Series devices running vulnerable versions, potentially causing PFE crashes and restarts.

💻 Affected Systems

Products:
  • Juniper Networks SRX Series
Versions: All versions before 21.3R3-S1, 21.4 versions before 21.4R3, 22.1 versions before 22.1R2, 22.2 versions before 22.2R1-S2 and 22.2R2
Operating Systems: Junos OS
Default Config Vulnerable: ⚠️ Yes
Notes: Requires ATP Cloud inspection to be enabled and processing traffic; timing-dependent so exploitation may be inconsistent

📦 What is this software?

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

Junos by Juniper

Junos OS is Juniper Networks' flagship network operating system running on enterprise routers, switches, security appliances, and data center infrastructure worldwide. Deployed across telecommunications providers, ISPs, cloud service providers, financial institutions, and large enterprises, Junos po...

Learn more about Junos →

⚠️ Risk & Real-World Impact

🔴

Worst Case

Complete denial of service with packet forwarding engine crashes and restarts, disrupting all network traffic through affected SRX devices

🟠

Likely Case

Intermittent service disruption during high traffic periods with ATP Cloud inspection enabled, requiring manual intervention or automatic restarts

🟢

If Mitigated

Minimal impact if traffic filtering prevents large volumes from reaching ATP Cloud inspection or if vulnerable versions are not deployed

🌐 Internet-Facing: HIGH - Unauthenticated network-based attack that can be triggered from external sources if ATP Cloud inspection processes internet traffic
🏢 Internal Only: MEDIUM - Internal attackers or misconfigured internal systems could trigger the deadlock, but requires ATP Cloud inspection traffic

🎯 Exploit Status

Public PoC: ✅ No
Weaponized: UNKNOWN
Unauthenticated Exploit: ⚠️ Yes
Complexity: MEDIUM

Exploitation requires sending large traffic volumes through ATP Cloud inspection and depends on system timing, making reliable exploitation challenging

🛠️ Fix & Mitigation

✅ Official Fix

Patch Version: 21.3R3-S1, 21.4R3, 22.1R2, 22.2R1-S2, or 22.2R2 depending on version branch

Vendor Advisory: https://supportportal.juniper.net/JSA88137

Restart Required: Yes

Instructions:

1. Check current Junos OS version with 'show version'. 2. Download appropriate fixed version from Juniper support portal. 3. Install update following Juniper upgrade procedures. 4. Reboot device to complete installation.

🔧 Temporary Workarounds

Disable ATP Cloud Inspection

all

Temporarily disable Advanced Threat Prevention Cloud inspection to prevent deadlock condition

set security utm advanced-threat-prevention cloud-inspection disable

Limit ATP Cloud Traffic

all

Configure traffic filtering to reduce volume sent to ATP Cloud inspection

set security utm advanced-threat-prevention profile <profile-name> rule <rule-name> match destination-address <address>
set security policies from-zone <zone> to-zone <zone> policy <policy-name> then permit application-services advanced-anti-malware-policy <policy>

🧯 If You Can't Patch

  • Implement strict traffic filtering to limit volume reaching ATP Cloud inspection
  • Monitor for PFE crash events and establish rapid response procedures for service restoration

🔍 How to Verify

Check if Vulnerable:

Run 'show version' and compare against affected version ranges; check if ATP Cloud inspection is enabled with 'show security utm advanced-threat-prevention status'

Check Version:

show version

Verify Fix Applied:

After patching, verify version with 'show version' matches fixed versions; monitor for PFE crashes during high traffic periods

📡 Detection & Monitoring

Log Indicators:

  • PFE crash messages in system logs
  • ATP Cloud inspection process failures
  • High CPU/memory usage before service disruption

Network Indicators:

  • Sudden traffic drops through SRX device
  • Increased packet loss during high traffic periods

SIEM Query:

source="junos" AND ("PFE crash" OR "deadlock" OR "ATP Cloud" AND "failure")

🔗 References

📤 Share & Export