An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows a unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When MPLS packets are meant to be sent to a flexible tunnel interface (FTI) and if the FTI tunnel is down, these will hit the reject NH, due to which the packets get sent to the CPU and cause a host path wedge condition. This will cause the FPC to hang and requires a manual restart to recover. Please note that this issue specifically affects PTX1000, PTX3000, PTX5000 with FPC3, PTX10002-60C, and PTX10008/16 with LC110x. Other PTX Series devices and Line Cards (LC) are not affected. The following log message can be seen when the issue occurs: Cmerror Op Set: Host Loopback: HOST LOOPBACK WEDGE DETECTED IN PATH ID <id> (URI: /fpc/<fpc>/pfe/<pfe>/cm/<cm>/Host_Loopback/<cm>/HOST_LOOPBACK_MAKE_CMERROR_ID[<id>]) This issue affects Juniper Networks Junos OS: * All versions earlier than 20.4R3-S8; * 21.1 versions earlier than 21.1R3-S4; * 21.2 versions earlier than 21.2R3-S6; * 21.3 versions earlier than 21.3R3-S3; * 21.4 versions earlier than 21.4R3-S5; * 22.1 versions earlier than 22.1R2-S2, 22.1R3; * 22.2 versions earlier than 22.2R2-S1, 22.2R3.
Conclusion & alert: CVE-2024-21600 is rated Low Risk (34.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.32%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.04% | 0.32% | +0.28% |
| 2 | 2025-11-21 | 0.10% | 0.04% | -0.05% |
| 3 | 2025-11-18 | — | 0.10% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:-:*:*:*:*:*:* |
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:r1:*:*:*:*:*:* |
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:r1-s1:*:*:*:*:*:* |
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:r2:*:*:*:*:*:* |
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:r2-s1:*:*:*:*:*:* |
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:r2-s2:*:*:*:*:*:* |
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:r3:*:*:*:*:*:* |
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:r3-s1:*:*:*:*:*:* |
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:r3-s2:*:*:*:*:*:* |
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:r3-s3:*:*:*:*:*:* |
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:r3-s4:*:*:*:*:*:* |
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:r3-s5:*:*:*:*:*:* |
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:r3-s6:*:*:*:*:*:* |
| juniper | junos | 20.4 | cpe:2.3:o:juniper:junos:20.4:r3-s7:*:*:*:*:*:* |
| juniper | junos | 21.1 | cpe:2.3:o:juniper:junos:21.1:-:*:*:*:*:*:* |
| juniper | junos | 21.1 | cpe:2.3:o:juniper:junos:21.1:r1:*:*:*:*:*:* |
| juniper | junos | 21.1 | cpe:2.3:o:juniper:junos:21.1:r1-s1:*:*:*:*:*:* |
| juniper | junos | 21.1 | cpe:2.3:o:juniper:junos:21.1:r2:*:*:*:*:*:* |
| juniper | junos | 21.1 | cpe:2.3:o:juniper:junos:21.1:r2-s1:*:*:*:*:*:* |
| juniper | junos | 21.1 | cpe:2.3:o:juniper:junos:21.1:r2-s2:*:*:*:*:*:* |
| juniper | junos | 21.1 | cpe:2.3:o:juniper:junos:21.1:r3:*:*:*:*:*:* |
| juniper | junos | 21.1 | cpe:2.3:o:juniper:junos:21.1:r3-s1:*:*:*:*:*:* |
| juniper | junos | 21.1 | cpe:2.3:o:juniper:junos:21.1:r3-s2:*:*:*:*:*:* |
| juniper | junos | 21.1 | cpe:2.3:o:juniper:junos:21.1:r3-s3:*:*:*:*:*:* |
| juniper | junos | 21.2 | cpe:2.3:o:juniper:junos:21.2:-:*:*:*:*:*:* |
| juniper | junos | 21.2 | cpe:2.3:o:juniper:junos:21.2:r1:*:*:*:*:*:* |
| juniper | junos | 21.2 | cpe:2.3:o:juniper:junos:21.2:r1-s1:*:*:*:*:*:* |
| juniper | junos | 21.2 | cpe:2.3:o:juniper:junos:21.2:r1-s2:*:*:*:*:*:* |
| juniper | junos | 21.2 | cpe:2.3:o:juniper:junos:21.2:r2:*:*:*:*:*:* |
| juniper | junos | 21.2 | cpe:2.3:o:juniper:junos:21.2:r2-s1:*:*:*:*:*:* |
| juniper | junos | 21.2 | cpe:2.3:o:juniper:junos:21.2:r2-s2:*:*:*:*:*:* |
| juniper | junos | 21.2 | cpe:2.3:o:juniper:junos:21.2:r3:*:*:*:*:*:* |
| juniper | junos | 21.2 | cpe:2.3:o:juniper:junos:21.2:r3-s1:*:*:*:*:*:* |
| juniper | junos | 21.2 | cpe:2.3:o:juniper:junos:21.2:r3-s2:*:*:*:*:*:* |
| juniper | junos | 21.2 | cpe:2.3:o:juniper:junos:21.2:r3-s3:*:*:*:*:*:* |
| juniper | junos | 21.2 | cpe:2.3:o:juniper:junos:21.2:r3-s4:*:*:*:*:*:* |
| juniper | junos | 21.2 | cpe:2.3:o:juniper:junos:21.2:r3-s5:*:*:*:*:*:* |
| juniper | junos | 21.3 | cpe:2.3:o:juniper:junos:21.3:-:*:*:*:*:*:* |
| juniper | junos | 21.3 | cpe:2.3:o:juniper:junos:21.3:r1:*:*:*:*:*:* |
| juniper | junos | 21.3 | cpe:2.3:o:juniper:junos:21.3:r1-s1:*:*:*:*:*:* |
| juniper | junos | 21.3 | cpe:2.3:o:juniper:junos:21.3:r1-s2:*:*:*:*:*:* |
| juniper | junos | 21.3 | cpe:2.3:o:juniper:junos:21.3:r2:*:*:*:*:*:* |
| juniper | junos | 21.3 | cpe:2.3:o:juniper:junos:21.3:r2-s1:*:*:*:*:*:* |
| juniper | junos | 21.3 | cpe:2.3:o:juniper:junos:21.3:r2-s2:*:*:*:*:*:* |
| juniper | junos | 21.3 | cpe:2.3:o:juniper:junos:21.3:r3:*:*:*:*:*:* |
| juniper | junos | 21.3 | cpe:2.3:o:juniper:junos:21.3:r3-s1:*:*:*:*:*:* |
| juniper | junos | 21.3 | cpe:2.3:o:juniper:junos:21.3:r3-s2:*:*:*:*:*:* |
| juniper | junos | 21.4 | cpe:2.3:o:juniper:junos:21.4:-:*:*:*:*:*:* |
| juniper | junos | 21.4 | cpe:2.3:o:juniper:junos:21.4:r1:*:*:*:*:*:* |
| juniper | junos | 21.4 | cpe:2.3:o:juniper:junos:21.4:r1-s1:*:*:*:*:*:* |
| juniper | junos | 21.4 | cpe:2.3:o:juniper:junos:21.4:r1-s2:*:*:*:*:*:* |
| juniper | junos | 21.4 | cpe:2.3:o:juniper:junos:21.4:r2:*:*:*:*:*:* |
| juniper | junos | 21.4 | cpe:2.3:o:juniper:junos:21.4:r2-s1:*:*:*:*:*:* |
| juniper | junos | 21.4 | cpe:2.3:o:juniper:junos:21.4:r2-s2:*:*:*:*:*:* |
| juniper | junos | 21.4 | cpe:2.3:o:juniper:junos:21.4:r3:*:*:*:*:*:* |
| juniper | junos | 21.4 | cpe:2.3:o:juniper:junos:21.4:r3-s1:*:*:*:*:*:* |
| juniper | junos | 21.4 | cpe:2.3:o:juniper:junos:21.4:r3-s2:*:*:*:*:*:* |
| juniper | junos | 21.4 | cpe:2.3:o:juniper:junos:21.4:r3-s3:*:*:*:*:*:* |
| juniper | junos | 21.4 | cpe:2.3:o:juniper:junos:21.4:r3-s4:*:*:*:*:*:* |
| juniper | junos | 22.1 | cpe:2.3:o:juniper:junos:22.1:-:*:*:*:*:*:* |
| juniper | junos | 22.1 | cpe:2.3:o:juniper:junos:22.1:r1:*:*:*:*:*:* |
| juniper | junos | 22.1 | cpe:2.3:o:juniper:junos:22.1:r1-s1:*:*:*:*:*:* |
| juniper | junos | 22.1 | cpe:2.3:o:juniper:junos:22.1:r1-s2:*:*:*:*:*:* |
| juniper | junos | 22.1 | cpe:2.3:o:juniper:junos:22.1:r2:*:*:*:*:*:* |
| juniper | junos | 22.1 | cpe:2.3:o:juniper:junos:22.1:r2-s1:*:*:*:*:*:* |
| juniper | junos | 22.2 | cpe:2.3:o:juniper:junos:22.2:-:*:*:*:*:*:* |
| juniper | junos | 22.2 | cpe:2.3:o:juniper:junos:22.2:r1:*:*:*:*:*:* |
| juniper | junos | 22.2 | cpe:2.3:o:juniper:junos:22.2:r1-s1:*:*:*:*:*:* |
| juniper | junos | 22.2 | cpe:2.3:o:juniper:junos:22.2:r1-s2:*:*:*:*:*:* |
| juniper | junos | 22.2 | cpe:2.3:o:juniper:junos:22.2:r2:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://supportportal.juniper.net/JSA75741 | Vendor Advisory |
| https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L | Third Party Advisory |