Cyber Resilience

CVE-2024-47498

Juniper Junos Os Evolved ≤ 21.4

Published
11 October 2024
Modified
26 January 2026
Patch / advisory
CVSS Score v4 7.1
Click a component to see what it means
Raw vectorCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0033 26th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2024-47498 is a high-severity an unspecified weakness vulnerability in Juniper Junos Os Evolved. Its CVSS base score is 7.1 (High).

Operationally, ranked at the 26th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS Evolved on QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Several configuration statements meant to enforce limits on MAC learning…

more

and moves can be configured but do not take effect. This can lead to control plane overload situations which will severely impact the ability of the device to processes legitimate traffic. This issue affects Junos OS Evolved on QFX5000 Series: * All versions before 21.4R3-S8-EVO, * 22.2-EVO versions before 22.2R3-S5-EVO, * 22.4-EVO versions before 22.4R3-EVO, * 23.2-EVO versions before 23.2R2-EVO.

CWE(s)

Related Threats

CVEs Like This One

CVE-2026-57029Same product: Juniper Junos Os Evolved
CVE-2025-59957Same product: Juniper Qfx5110
CVE-2024-39533Same product: Juniper Qfx5110
CVE-2024-30388Same product: Juniper Qfx5110
CVE-2026-21910Same product: Juniper Qfx5110
CVE-2025-30644Same product: Juniper Qfx5110
CVE-2026-33781Same product: Juniper Qfx5110
CVE-2026-33773Same product: Juniper Qfx5110
CVE-2024-21595Same product: Juniper Qfx5110
CVE-2023-22405Same product: Juniper Qfx5110

Affected Assets

juniper
junos os evolved
21.4, 22.2, 22.4, 23.2 · ≤ 21.4

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References