An Improper Handling of Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows a network-based, unauthenticated attacker to cause a Denial-of-Service (DoS). If a value is configured for DDoS bandwidth or burst parameters for any protocol in a queue, all protocols which share the same queue will have their bandwidth or burst value changed to the new value. If, for example, OSPF was configured with a certain bandwidth value, ISIS would also be limited to this value. So inadvertently either the control plane is open for a high level of specific traffic which was supposed to be limited to a lower value, or the limit for a certain protocol is so low that chances to succeed with a volumetric DoS attack are significantly increased. This issue affects Junos OS Evolved on ACX 7000 Series: * All versions before 21.4R3-S7-EVO, * 22.1 versions before 22.1R3-S6-EVO, * 22.2 versions before 22.2R3-S3-EVO, * 22.3 versions before 22.3R3-S3-EVO, * 22.4 versions before 22.4R3-S2-EVO, * 23.2 versions before 23.2R2-EVO, * 23.4 versions before 23.4R1-S1-EVO, 23.4R2-EVO.
Conclusion & alert: CVE-2024-39531 is rated Moderate Risk (46.9/100): CVSS High severity, with low exploitation likelihood (EPSS 0.44%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.50% | 0.44% | -0.06% |
| 2 | 2026-01-23 | 0.25% | 0.50% | +0.24% |
| 3 | 2025-11-21 | — | 0.25% | — |
Full EPSS history (12 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.7 | 4.0 | HIGH |
|
— | — | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| juniper | junos_os_evolved | < 21.4 | cpe:2.3:o:juniper:junos_os_evolved:*:*:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:-:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:r1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:r1-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:r1-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:r2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:r2-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:r2-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:r3:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:r3-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:r3-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:r3-s3:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:r3-s4:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:r3-s5:*:*:*:*:*:* |
| juniper | junos_os_evolved | 21.4 | cpe:2.3:o:juniper:junos_os_evolved:21.4:r3-s6:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.1 | cpe:2.3:o:juniper:junos_os_evolved:22.1:-:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.1 | cpe:2.3:o:juniper:junos_os_evolved:22.1:r1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.1 | cpe:2.3:o:juniper:junos_os_evolved:22.1:r1-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.1 | cpe:2.3:o:juniper:junos_os_evolved:22.1:r1-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.1 | cpe:2.3:o:juniper:junos_os_evolved:22.1:r2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.1 | cpe:2.3:o:juniper:junos_os_evolved:22.1:r2-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.1 | cpe:2.3:o:juniper:junos_os_evolved:22.1:r3:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.1 | cpe:2.3:o:juniper:junos_os_evolved:22.1:r3-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.1 | cpe:2.3:o:juniper:junos_os_evolved:22.1:r3-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.1 | cpe:2.3:o:juniper:junos_os_evolved:22.1:r3-s3:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.1 | cpe:2.3:o:juniper:junos_os_evolved:22.1:r3-s4:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.1 | cpe:2.3:o:juniper:junos_os_evolved:22.1:r3-s5:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.2 | cpe:2.3:o:juniper:junos_os_evolved:22.2:-:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.2 | cpe:2.3:o:juniper:junos_os_evolved:22.2:r1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.2 | cpe:2.3:o:juniper:junos_os_evolved:22.2:r1-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.2 | cpe:2.3:o:juniper:junos_os_evolved:22.2:r1-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.2 | cpe:2.3:o:juniper:junos_os_evolved:22.2:r2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.2 | cpe:2.3:o:juniper:junos_os_evolved:22.2:r2-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.2 | cpe:2.3:o:juniper:junos_os_evolved:22.2:r2-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.2 | cpe:2.3:o:juniper:junos_os_evolved:22.2:r3:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.2 | cpe:2.3:o:juniper:junos_os_evolved:22.2:r3-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.2 | cpe:2.3:o:juniper:junos_os_evolved:22.2:r3-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.3 | cpe:2.3:o:juniper:junos_os_evolved:22.3:-:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.3 | cpe:2.3:o:juniper:junos_os_evolved:22.3:r1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.3 | cpe:2.3:o:juniper:junos_os_evolved:22.3:r1-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.3 | cpe:2.3:o:juniper:junos_os_evolved:22.3:r1-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.3 | cpe:2.3:o:juniper:junos_os_evolved:22.3:r2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.3 | cpe:2.3:o:juniper:junos_os_evolved:22.3:r2-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.3 | cpe:2.3:o:juniper:junos_os_evolved:22.3:r2-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.3 | cpe:2.3:o:juniper:junos_os_evolved:22.3:r3:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.3 | cpe:2.3:o:juniper:junos_os_evolved:22.3:r3-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.3 | cpe:2.3:o:juniper:junos_os_evolved:22.3:r3-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.4 | cpe:2.3:o:juniper:junos_os_evolved:22.4:-:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.4 | cpe:2.3:o:juniper:junos_os_evolved:22.4:r1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.4 | cpe:2.3:o:juniper:junos_os_evolved:22.4:r1-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.4 | cpe:2.3:o:juniper:junos_os_evolved:22.4:r1-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.4 | cpe:2.3:o:juniper:junos_os_evolved:22.4:r2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.4 | cpe:2.3:o:juniper:junos_os_evolved:22.4:r2-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.4 | cpe:2.3:o:juniper:junos_os_evolved:22.4:r2-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.4 | cpe:2.3:o:juniper:junos_os_evolved:22.4:r3:*:*:*:*:*:* |
| juniper | junos_os_evolved | 22.4 | cpe:2.3:o:juniper:junos_os_evolved:22.4:r3-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 23.2 | cpe:2.3:o:juniper:junos_os_evolved:23.2:-:*:*:*:*:*:* |
| juniper | junos_os_evolved | 23.2 | cpe:2.3:o:juniper:junos_os_evolved:23.2:r1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 23.2 | cpe:2.3:o:juniper:junos_os_evolved:23.2:r1-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 23.2 | cpe:2.3:o:juniper:junos_os_evolved:23.2:r1-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 23.4 | cpe:2.3:o:juniper:junos_os_evolved:23.4:-:*:*:*:*:*:* |
| juniper | junos_os_evolved | 23.4 | cpe:2.3:o:juniper:junos_os_evolved:23.4:r1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 23.4 | cpe:2.3:o:juniper:junos_os_evolved:23.4:r2:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://supportportal.juniper.net/JSA82991 | Vendor Advisory |