Skip to content

Instantly share code, notes, and snippets.

View ViperGeek's full-sized avatar

Dave Dugal ViperGeek

View GitHub Profile
@ViperGeek
ViperGeek / gist:0eb052ff8fc681363b0e6c8284ccb351
Created April 18, 2024 17:23
Juniper 2024-04 CVSS v3+v4 Scores
CVE-2024-30395: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash
CVSS 3.1: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 4.0: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
CVE-2024-30409: Higher CPU consumption on routing engine leads to Denial of Service
CVSS 3.1: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 4.0: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVE-2024-21610: In a scaled subscriber scenario if CoS information is gathered mgd processes gets stuck
CVSS 3.1: 4.3 CVSS:3.1/AV:N/AC:L/PR:l/UI:N/S:U/C:N/I:N/A:L

openpgp4fpr:5D2461C5666F73A33AA8E043C5BBC32B0B71727A

CVE-CNA Discord proof

I hereby claim:

  • I am ViperGeek on GitHub.
  • I am @ViperGeek#6262 (363860130556805127) on Discord.
  • Juniper Networks is a CVE Partner CNA.
  • CVE_data_meta: ASSIGNER: sirt@juniper.net

Keybase proof

I hereby claim:

  • I am vipergeek on github.
  • I am vipergeek (https://keybase.io/vipergeek) on keybase.
  • I have a public key ASDbzkae5Se8UCLuStPz3-96_kyBsLQXBDzKrK4U1yRGNwo

To claim this, I am signing this object: