Where
AND
-Infinity
0
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker sending a specific malformed BGP update message to cause the session to reset, resulting in a Denial of Service (DoS). Continued receipt and processing of these malformed BGP update messages will create a sustained Denial of Service (DoS) condition.

Upon receipt of a BGP update message over an established BGP session containing a specifically malformed tunnel encapsulation attribute, when segment routing is enabled, internal processing of the malformed attributes within the update results in improper parsing of remaining attributes, leading to session reset:

BGP SEND Notification code 3 (Update Message Error) subcode 1 (invalid attribute list)

Only systems with segment routing enabled are vulnerable to this issue.

This issue affects eBGP and iBGP, in both IPv4 and IPv6 implementations, and requires a remote attacker to have at least one established BGP session.

This issue affects:

Junos OS:

All versions before 21.4R3-S8, from 22.2 before 22.2R3-S4, from 22.3 before 22.3R3-S3, from 22.4 before 22.4R3-S3, from 23.2 before 23.2R2-S1, from 23.4 before 23.4R1-S2, 23.4R2.

Junos OS Evolved:

All versions before 21.4R3-S8-EVO, from 22.2-EVO before 22.2R3-S4-EVO, from 22.3-EVO before 22.3R3-S3-EVO, from 22.4-EVO before 22.4R3-S3-EVO, from 23.2-EVO before 23.2R2-S1-EVO, from 23.4-EVO before 23.4R1-S2-EVO, 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 21.4R3-S8, 22.2R3-S4, 22.3R3-S3, 22.4R3-S3, 23.2R2-S1, 23.4R1-S2, 23.4R2, 24.2R1, and all subsequent releases. Junos OS Evolved: 21.4R3-S8-EVO, 22.2R3-S4-EVO, 22.3R3-S3-EVO, 22.4R3-S3-EVO, 23.2R2-S1-EVO, 23.4R1-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This memory is not properly freed in all circumstances, leading to a Denial of Service (DoS).

Consumed memory can be freed by manually restarting Routing Protocol Daemon (rpd).

Memory utilization could be monitored by:  user@host> show system memory or show system monitor memory status

This issue affects:

Junos OS:  All versions before 21.2R3-S8,  from 21.4 before 21.4R3-S8,

from 22.2 before 22.2R3-S4,  from 22.3 before 22.3R3-S3,  from 22.4 before 22.4R3-S3, from 23.2 before 23.2R2-S1,  from 23.4 before 23.4R1-S2, 23.4R2.

Junos OS Evolved: All versions before 21.2R3-S8-EVO, from 21.4 before 21.4R3-S8-EVO, from 22.2 before 22.2R3-S4-EVO, from 22.3 before 22.3R3-S3-EVO, from 22.4 before 22.4R3-S3-EVO,

from 23.2 before 23.2R2-S1-EVO, from 23.4 before 23.4R1-S2-EVO, 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 21.2R3-S8, 21.4R3-S8, 22.2R3-S4, 22.3R3-S3, 22.4R3-S3, 23.2R2-S1, 23.4R1-S2, 23.4R2, 24.2R1, and all subsequent releases. Junos OS Evolved: 21.2R3-S8-EVO, 21.4R3-S8-EVO, 22.2R3-S4-EVO, 22.3R3-S3-EVO, 22.4R3-S3-EVO, 23.2R2-S1-EVO, 23.4R1-S2-EVO, 23.4R2-EVO, 24.2R1-EVO and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Out-of-Bounds Read vulnerability in

the routing protocol daemon (rpd) of

Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.

This issue only affects systems configured in either of two ways:

systems with BGP traceoptions enabled

systems with BGP traffic engineering configured

This issue can affect iBGP and eBGP with

any address family

configured. The specific attribute involved is non-transitive, and will not propagate across a network.

This issue affects:

Junos OS:

All versions before 21.4R3-S8, 22.2 before 22.2R3-S5,  22.3 before 22.3R3-S4,  22.4 before 22.4R3-S3,  23.2 before 23.2R2-S2,  23.4 before 23.4R2;

Junos OS Evolved:

All versions before 21.4R3-S8-EVO,  22.2-EVO before 22.2R3-S5-EVO,  22.3-EVO before 22.3R3-S4-EVO,  22.4-EVO before 22.4R3-S3-EVO,  23.2-EVO before 23.2R2-S2-EVO,  23.4-EVO before 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 21.4R3-S8, 22.2R3-S5*, 22.3R3-S4*, 22.4R3-S3, 23.2R2-S2, 23.4R2, 24.2R1, and all subsequent releases. Junos OS Evolved: 21.4R3-S8-EVO, 22.2R3-S5-EVO*, 22.3R3-S4-EVO*, 22.4R3-S3-EVO, 23.2R2-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, 24.2R2-EVO, 24.4R1-EVO*, and all subsequent releases. *Future release
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specific BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.

This issue only affects systems with BGP traceoptions enabled and

requires a BGP session to be already established.  Systems without BGP traceoptions enabled are not affected by this issue.

This issue affects iBGP and eBGP, and both IPv4 and IPv6 are affected by this vulnerability.

This issue affects:

Junos OS:

All versions before 21.2R3-S8,  from 21.4 before 21.4R3-S8,  from 22.2 before 22.2R3-S4,  from 22.3 before 22.3R3-S4, from 22.4 before 22.4R3-S3,  from 23.2 before 23.2R2-S1,  from 23.4 before 23.4R2;

Junos OS Evolved:

All versions before 21.2R3-S8-EVO,  from 21.4-EVO before 21.4R3-S8-EVO,  from 22.2-EVO before 22.2R3-S4-EVO,  from 22.3-EVO before 22.3R3-S4-EVO, from 22.4-EVO before 22.4R3-S3-EVO,  from 23.2-EVO before 23.2R2-S1-EVO,  from 23.4-EVO before 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 21.2R3-S8, 21.4R3-S8, 22.2R3-S4, 22.3R3-S4*, 22.4R3-S3, 23.2R2-S1, 23.4R2, 24.2R1, and all subsequent releases. Junos OS Evolved 21.2R3-S8-EVO, 21.4R3-S8-EVO, 22.2R3-S4-EVO, 22.3R3-S4-EVO*, 22.4R3-S3-EVO, 23.2R2-S1-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases. *Future release
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.

In some cases, rpd fails to restart requiring a manual restart via the 'restart routing' CLI command.

This issue only affects systems with BGP traceoptions enabled and

requires a BGP session to be already established. Systems without BGP traceoptions enabled are not affected by this issue.

This issue affects iBGP and eBGP, and both IPv4 and IPv6 are affected by this vulnerability.

This issue affects:

Junos OS:

All versions before 21.4R3-S8,  22.2 before 22.2R3-S5,  22.3 before 22.3R3-S4,  22.4 before 22.4R3-S3,  23.2 before 23.2R2-S2,  23.4 before 23.4R2;

Junos OS Evolved:

All versions before 21.4R3-S8-EVO,  22.2-EVO before 22.2R3-S5-EVO,  22.3-EVO before 22.3R3-S4-EVO,  22.4-EVO before 22.4R3-S3-EVO,  23.2-EVO before 23.2R2-S2-EVO,  23.4-EVO before 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 21.4R3-S8, 22.2R3-S5*, 22.3R3-S4*, 22.4R3-S3, 23.2R2-S2, 23.4R2, 24.2R1, and all subsequent releases. Junos OS Evolved: 21.4R3-S8-EVO, 22.2R3-S5-EVO*, 22.3R3-S4-EVO*, 22.4R3-S3-EVO, 23.2R2-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, 24.2R2-EVO, 24.4R1-EVO*, and all subsequent releases. *Future release
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series, QFX Series, MX Series and EX Series allows an unauthenticated, network-based attacker to cause Denial-of-Service (DoS).

An attacker can send specific HTTPS connection requests to the device, triggering the creation of processes that are not properly terminated. Over time, this leads to resource exhaustion, ultimately causing the device to crash and restart.

The following command can be used to monitor the resource usage: user@host> show system processes extensive | match mgd | count

This issue affects Junos OS on SRX Series and EX Series: All versions before 21.4R3-S7, from 22.2 before 22.2R3-S4, from 22.3 before 22.3R3-S3, from 22.4 before 22.4R3-S2, from 23.2 before 23.2R2-S1, from 23.4 before 23.4R1-S2, 23.4R2.

First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS).

In a scenario where BGP Monitoring Protocol (BMP) is configured with rib-in pre-policy monitoring, receiving a BGP update with a specifically malformed AS PATH attribute over an established BGP session, can cause an RPD crash and restart.

This issue affects:

Junos OS:

All versions before 21.2R3-S8, 21.4 versions before 21.4R3-S8, 22.2 versions before 22.2R3-S4, 22.3 versions before 22.3R3-S3, 22.4 versions before 22.4R3-S2, 23.2 versions before 23.2R2-S1, 23.4 versions before 23.4R1-S2, 23.4R2;

Junos OS Evolved:

All versions before 21.2R3-S8-EVO, 21.4 versions before 21.4R3-S8-EVO, 22.2 versions before 22.2R3-S4-EVO, 22.3 versions before 22.3R3-S3-EVO, 22.4 versions before 22.4R3-S2-EVO, 23.2 versions before 23.2R2-S1-EVO, 23.4 versions before 23.4R1-S2-EVO, 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 21.2R3-S8-EVO, 21.4R3-S8-EVO, 22.2R3-S4-EVO, 22.3R3-S3-EVO, 22.4R3-S2-EVO, 23.2R2-S1-EVO, 23.4R1-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases; Junos OS: 21.2R3-S8, 21.4R3-S8, 22.2R3-S4, 22.3R3-S3, 22.4R3-S2, 23.2R2-S1, 23.4R1-S2, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Validation of Specified Type of Input vulnerability in the packet forwarding engine (pfe) Juniper Networks Junos OS on SRX5000 Series allows an unauthenticated, network based attacker to cause a Denial of Service (Dos).

When a non-clustered SRX5000 device receives a specifically malformed packet this will cause a flowd crash and restart.

This issue affects Junos OS:

22.1 releases 22.1R1 and later before 22.2R3-S5, 22.3 releases before 22.3R3-S4, 22.4 releases before 22.4R3-S4, 23.2 releases before 23.2R2-S2, 23.4 releases before 23.4R2-S1, 24.2 releases before 24.2R1-S1, 24.2R2.

Please note that the PR does indicate that earlier versions have been fixed as well, but these won't be adversely impacted by this.

Remedy

The following software releases have been updated to resolve this specific issue: 22.2R3-S5*, 22.3R3-S4*, 22.4R3-S4, 23.2R2-S2, 23.4R2-S1, 24.2R1-S1, 24.2R2*, 24.4R1*, and all subsequent releases. (* future release)
First published (updated )
Severity
8.7
Double Free
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

This is a similar, but different vulnerability than the issue reported as CVE-2024-39549.

A double-free vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This double free of memory is causing an rpd crash, leading to a Denial of Service (DoS).

This issue affects:

Junos OS:  from 22.4 before 22.4R3-S4.

Junos OS Evolved: from 22.4 before 22.4R3-S4-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 22.4R3-S4 and all subsequent releases. Junos OS Evolved: 22.4R3-S4-EVO and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the pfe (packet forwarding engine) of Juniper Networks Junos OS on MX Series causes a port within a pool to be blocked leading to Denial of Service (DoS).

In a DS-Lite (Dual-Stack Lite) and NAT (Network Address Translation) scenario, when crafted IPv6 traffic is received and prefix-length is set to 56, the ports assigned to the user will not be freed.  Eventually, users cannot establish new connections. Affected FPC/PIC need to be manually restarted to recover. Following is the command to identify the issue:

user@host> show services nat source port-block      HostIP                     ExternalIP                   PortBlock      PortsUsed/       BlockState/                                                               Range           PortsTotal       LeftTime(s)     2001::                        x.x.x.x                     58880-59391     256/2561         Active/-       >>>>>>>>port still usedThis issue affects Junos OS on MX Series:

from 21.2 before 21.2R3-S8,  from 21.4 before 21.4R3-S7,  from 22.1 before 22.1R3-S6,  from 22.2 before 22.2R3-S4,  from 22.3 before 22.3R3-S3,  from 22.4 before 22.4R3-S2,  from 23.2 before 23.2R2-S1,  from 23.4 before 23.4R1-S2, 23.4R2.

This issue does not affect versions before 20.2R1.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 21.2R3-S8, 21.4R3-S7, 22.1R3-S6, 22.2R3-S4, 22.3R3-S3, 22.4R3-S2, 23.2R2-S1, 23.4R1-S2, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )
Severity
8.7
Input Validation
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Input Validation vulnerability in the syslog stream TCP transport of Juniper Networks Junos OS on MX240, MX480 and MX960 devices with MX-SPC3 Security Services Card allows an unauthenticated, network-based attacker, to send specific spoofed packets to cause a CPU Denial of Service (DoS) to the MX-SPC3 SPUs.

Continued receipt and processing of these specific packets will sustain the DoS condition.

This issue affects Junos OS: All versions before 22.2R3-S6, from 22.4 before 22.4R3-S4, from 23.2 before 23.2R2-S3, from 23.4 before 23.4R2-S4, from 24.2 before 24.2R1-S2, 24.2R2

An indicator of compromise will indicate the SPC3 SPUs utilization has spiked.

For example:     user@device> show services service-sets summary Service sets CPU Interface configured Bytes used Session bytes used Policy bytes used utilization "interface" 1 "bytes" (percent%) "sessions" ("percent"%) "bytes" ("percent"%) 99.97 % OVLD <<<<<< look for high CPU usage

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 22.2R3-S6, 22.4R3-S4, 23.2R2-S3, 23.4R2-S4, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
Null Pointer Dereference
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A NULL Pointer Dereference vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker causing specific, valid control traffic to be sent out of a Dual-Stack (DS) Lite tunnel to crash the flowd process, resulting in a Denial of Service (DoS).  Continuous triggering of specific control traffic will create a sustained Denial of Service (DoS) condition.

On all SRX platforms, when specific, valid control traffic needs to be sent out of a DS-Lite tunnel, a segmentation fault occurs within the flowd process, resulting in a network outage until the flowd process restarts.

This issue affects Junos OS on SRX Series: All versions before 21.2R3-S9, from 21.4 before 21.4R3-S9, from 22.2 before 22.2R3-S5, from 22.4 before 22.4R3-S6, from 23.2 before 23.2R2-S3, from 23.4 before 23.4R2.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 21.2R3-S9, 21.4R3-S9, 22.2R3-S5, 22.4R3-S6, 23.2R2-S3, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Buffer Access with Incorrect Length Value vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When an attacker sends a specific ICMPv6 packet to an interface with "protocols router-advertisement" configured, rpd crashes and restarts. Continued receipt of this packet will cause a sustained DoS condition.

This issue only affects systems configured with IPv6.

This issue affects Junos OS:

All versions before 21.2R3-S9,  from 21.4 before 21.4R3-S10, from 22.2 before 22.2R3-S6, from 22.4 before 22.4R3-S4, from 23.2 before 23.2R2-S2, from 23.4 before 23.4R2;

and Junos OS Evolved: All versions before 21.2R3-S9-EVO, from 21.4-EVO before 21.4R3-S10-EVO, from 22.2-EVO before 22.2R3-S6-EVO, from 22.4-EVO before 22.4R3-S4-EVO, from 23.2-EVO before 23.2R2-S2-EVO, from 23.4-EVO before 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue:  Junos OS: 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S4, 23.2R2-S2, 23.4R2, 24.2R1, and all subsequent releases. Junos OS Evolved: 21.2R3-S9-EVO, 21.4R3-S10-EVO, 22.2R3-S6-EVO, 22.4R3-S4-EVO, 23.2R2-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Handling of Additional Special Element vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with MS-MPC, MS-MIC and SPC3, and SRX Series, allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

If the SIP ALG processes specifically formatted SIP invites, a memory corruption will occur which will lead to a crash of the FPC processing these packets. Although the system will automatically recover with the restart of the FPC, subsequent SIP invites will cause the crash again and lead to a sustained DoS.

This issue affects Junos OS on MX Series and SRX Series:

all versions before 21.2R3-S9, 21.4 versions before 21.4R3-S10, 22.2 versions before 22.2R3-S6, 22.4 versions before 22.4R3-S5, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S3, 24.2 versions before 24.2R1-S2, 24.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S5, 23.2R2-S3, 23.4R2-S3, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Handling of Length Parameter Inconsistency vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

When a device configured for Secure Vector Routing (SVR) receives a specifically malformed packet the PFE will crash and restart. This issue affects Junos OS on SRX Series:

All 21.4 versions, 22.2 versions before 22.2R3-S6, 22.4 versions before 22.4R3-S6, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2.

This issue does not affect versions before 21.4.

Remedy

The following software releases have been updated to resolve this specific issue: 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 23.4R2-S4, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Missing Release of Memory after Effective Lifetime vulnerability in the Anti-Virus processing of Juniper Networks Junos OS on SRX Series

allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

On all SRX platforms with Anti-Virus enabled, if a server sends specific content in the HTTP body of a response to a client request, these packets are queued by Anti-Virus processing in Juniper Buffers (jbufs) which are never released. When these jbufs are exhausted, the device stops forwarding all transit traffic.

A jbuf memory leak can be noticed from the following logs:

(<node>.)<fpc> Warning: jbuf pool id <#> utilization level (<current level>%) is above <threshold>%!

To recover from this issue, the affected device needs to be manually rebooted to free the leaked jbufs.

This issue affects Junos OS on SRX Series:

all versions before 21.2R3-S9, 21.4 versions before 21.4R3-S10, 22.2 versions before 22.2R3-S6, 22.4 versions before 22.4R3-S6, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S3, 24.2 versions before 24.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 23.4R2-S3, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).When processing a high rate of specific GRE traffic destined to the device, the respective PFE will hang causing traffic forwarding to stop.

When this issue occurs the following logs can be observed:

<fpc #> MQSS(0): LI-3: Received a parcel with more than 512B accompanying data CHASSISDFPCASICERROR: ASIC Error detected <...>

This issue affects Junos OS:

all versions before 21.2R3-S9, 21.4 versions before 21.4R3-S8, 22.2 versions before 22.2R3-S4, 22.4 versions before 22.4R3-S5, 23.2 versions before 23.2R2-S2, 23.4 versions before 23.4R2.

Remedy

The following software releases have been updated to resolve this specific issue: 21.2R3-S9, 21.4R3-S8, 22.2R3-S4, 22.4R3-S5, 23.2R2-S2, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )
Severity
8.7
Use After Free
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Use After Free vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an attacker sending a BGP update with a specifically malformed AS PATH to cause rpd to crash, resulting in a Denial of Service (DoS). Continuous receipt of the malformed AS PATH attribute will cause a sustained DoS condition.

On all Junos OS and Junos OS Evolved platforms, the rpd process will crash and restart when a specifically malformed AS PATH is received within a BGP update and traceoptions are enabled.

This issue only affects systems with BGP traceoptions enabled and requires a BGP session to be already established. Systems without BGP traceoptions enabled are not impacted by this issue.

This issue affects:

Junos OS:

All versions before 21.2R3-S9,  all versions of 21.4, from 22.2 before 22.2R3-S6,  from 22.4 before 22.4R3-S5,  from 23.2 before 23.2R2-S3,  from 23.4 before 23.4R2-S4,  from 24.2 before 24.2R2;

Junos OS Evolved:

All versions before 22.4R3-S5-EVO,  from 23.2-EVO before 23.2R2-S3-EVO,  from 23.4-EVO before 23.4R2-S4-EVO,  from 24.2-EVO before 24.2R2-EVO.

This is a more complete fix for previously published CVE-2024-39549 (JSA83011).

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 21.2R3-S9, 22.2R3-S6, 22.4R3-S5, 23.2R2-S3, 23.4R2-S4, 24.2R2, 24.4R1, and all subsequent releases. Junos OS Evolved: 22.4R3-S5-EVO, 23.2R2-S3-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-EVO, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on

SRX1600, SRX2300, SRX 4000 Series, and SRX5000 Series with SPC3

allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

If a sequence of specific PIM packets is received, this will cause a flowd crash and restart.

This issue affects Junos OS:

all versions before 21.2R3-S9, 21.4 versions before 21.4R3-S11, 22.2 versions before 22.2R3-S7, 22.4 versions before 22.4R3-S6, 23.2 versions before 23.2R2-S4, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2.

This is a similar, but different vulnerability than the issue reported as

CVE-2024-47503, published in JSA88133.

First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Use of Incorrect Byte Ordering

vulnerability

in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS on SRX300 Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

When a BGP update is received over an established BGP session which contains a specific, valid, optional, transitive path attribute, rpd will crash and restart.

This issue affects eBGP and iBGP over IPv4 and IPv6.

This issue affects:

Junos OS:

22.1 versions from 22.1R1 before 22.2R3-S4, 22.3 versions before 22.3R3-S3, 22.4 versions before 22.4R3-S2, 23.2 versions before 23.2R2, 23.4 versions before 23.4R2.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 22.2R3-S4, 22.3R3-S3, 22.4R3-S2, 23.2R2, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

When an affected device receives a BGP update with a set of specific optional transitive attributes over an established peering session, rpd will crash and restart when attempting to advertise the received information to another peer. This issue can only happen if one or both of the BGP peers of the receiving session are non-4-byte-AS capable as determined from the advertised capabilities during BGP session establishment. Junos OS and Junos OS Evolved default behavior is 4-byte-AS capable unless this has been specifically disabled by configuring:

[ protocols bgp ... disable-4byte-as ]

Established BGP sessions can be checked by executing:

show bgp neighbor <IP address> | match "4 byte AS"

This issue affects:

Junos OS:

all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S5, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S2, 24.4 versions before 24.4R2;

Junos OS Evolved:

all versions before 22.4R3-S8-EVO, 23.2 versions before 23.2R2-S5-EVO, 23.4 versions before 23.4R2-S6-EVO, 24.2 versions before 24.2R2-S2-EVO, 24.4 versions before 24.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases; Junos OS: 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S2, 24.4R2, 25.2R1, and all subsequent releases.
First published (updated )
Severity
8.7
EPSS
0.05%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-SPC3 or MS-MPC allows an unauthenticated network-based attacker sending specific SIP messages over TCP to crash the flow management process, leading to a Denial of Service (DoS).

On SRX Series, and MX Series with MX-SPC3 or MS-MPC service cards, receipt of multiple SIP messages causes the SIP headers to be parsed incorrectly, eventually causing a continuous loop and leading to a watchdog timer expiration, crashing the flowd process on SRX Series and MX Series with MX-SPC3, or mspmand process on MX Series with MS-MPC.

This issue only occurs over TCP. SIP messages sent over UDP cannot trigger this issue.

This issue affects Junos OS on SRX Series and MX Series with MX-SPC3 and MS-MPC:

all versions before 21.2R3-S10,  from 21.4 before 21.4R3-S12,  from 22.4 before 22.4R3-S8,  from 23.2 before 23.2R2-S5,  from 23.4 before 23.4R2-S6,  from 24.2 before 24.2R2-S3,  from 24.4 before 24.4R2-S1,  from 25.2 before 25.2R1-S1, 25.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: 21.2R3-S10, 21.4R3-S12, 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S3, 24.4R2-S1, 25.2R1-S1, 25.2R2, 25.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
EPSS
0.04%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos).

If an SRX Series device receives a specifically malformed GPRS Tunnelling Protocol (GTP) Modify Bearer Request message, a lock is acquired and never released. This results in other threads not being able to acquire a lock themselves, causing a watchdog timeout leading to FPC crash and restart. This issue leads to a complete traffic outage until the device has automatically recovered.

This issue affects Junos OS on SRX Series:

all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S5, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S3, 24.4 versions before 24.4R2-S2, 25.2 versions before 25.2R1-S1, 25.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S3, 24.4R2-S2, 25.2R1-S1, 25.2R2, 25.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
EPSS
0.05%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated network-based attacker sending a specific ICMP packet through a GRE tunnel to cause the PFE to crash and restart.

When PowerMode IPsec (PMI) and GRE performance acceleration are enabled and the device receives a specific ICMP packet, a crash occurs in the SRX PFE, resulting in traffic loss. PMI is enabled by default, and GRE performance acceleration can be enabled by running the configuration command shown below. PMI is a mode of operation that provides IPsec performance improvements using Vector Packet Processing.

Note that PMI with GRE performance acceleration is only supported on specific SRX platforms. This issue affects Junos OS on the SRX Series:

all versions before 21.4R3-S12,  from 22.4 before 22.4R3-S8,  from 23.2 before 23.2R2-S5,  from 23.4 before 23.4R2-S5,  from 24.2 before 24.2R2-S3,  from 24.4 before 24.4R2-S1,  from 25.2 before 25.2R1-S1, 25.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 21.4R3-S12, 22.4R3-S8, 23.2R2-S5, 23.4R2-S5, 24.2R2-S3, 24.4R2-S1, 25.2R1-S1, 25.2R2, 25.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
EPSS
0.05%
Double Free
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX and MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX and MX Series platforms, when during TCP session establishment a specific sequence of packets is encountered a double free happens. This causes flowd to crash and the respective FPC to restart.

This issue affects Junos OS on SRX and MX Series:

all versions before 22.4R3-S7, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: 22.4R3-S7, 23.2R2-S3, 23.4R2-S4, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
EPSS
0.05%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

If an SRX Series device configured for DNS processing, receives a specifically formatted DNS request flowd will crash and restart, which causes a service interruption until the process has recovered.

This issue affects Junos OS on SRX Series:

23.4 versions before 23.4R2-S5, 24.2 versions before 24.2R2-S1, 24.4 versions before 24.4R2.

This issue does not affect Junos OS versions before 23.4R1.

Remedy

The following software releases have been updated to resolve this specific issue: 23.4R2-S5, 24.2R2-S1, 24.4R2, 24.4R2-S1, 25.2R1, and all subsequent releases.
First published (updated )
Severity
8.7
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to cause a memory leak, that will eventually cause a complete Denial-of-Service (DoS).

In a DHCPv6 over PPPoE, or DHCPv6 over VLAN with Active lease query or Bulk lease query scenario, every subscriber logout will leak a small amount of memory. When all available memory has been exhausted, jdhcpd will crash and restart which causes a complete service impact until the process has recovered.

The memory usage of jdhcpd can be monitored with:

user@host> show system processes extensive | match jdhcpd

This issue affects Junos OS:

all versions before 22.4R3-S1, 23.2 versions before 23.2R2, 23.4 versions before 23.4R2.

Remedy

The following software releases have been updated to resolve this specific issue: 22.4R3-S1, 23.2R2, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complete Denial-of-Service (DoS).

If an affected device receives a specifically malformed first ISAKMP packet from the initiator, the kmd/iked process will crash and restart, which momentarily prevents new security associations (SAs) for from being established. Repeated exploitation of this vulnerability causes a complete inability to establish new VPN connections.

This issue affects Junos OS on

SRX Series and MX Series:

all versions before 22.4R3-S9, 23.2 version before 23.2R2-S6, 23.4 version before 23.4R2-S7, 24.2 versions before 24.2R2-S4, 24.4 versions before 24.4R2-S3, 25.2 versions before 25.2R1-S2, 25.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: 22.4R3-S9, 23.2R2-S6, 23.4R2-S7, 24.2R2-S4, 24.4R2-S3, 25.2R1-S2, 25.2R2, 25.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker sending a specific, malformed ICMPv6 packet to cause the srxpfe process to crash and restart. Continued receipt and processing of these packets will repeatedly crash the srxpfe process and sustain the Denial of Service (DoS) condition.

During NAT64 translation, receipt of a specific, malformed ICMPv6 packet destined to the device will cause the srxpfe process to crash and restart.

This issue cannot be triggered using IPv4 nor other IPv6 traffic.

This issue affects Junos OS on SRX Series: all versions before 21.2R3-S10, all versions of 21.3, from 21.4 before 21.4R3-S12, all versions of 22.1, from 22.2 before 22.2R3-S8, all versions of 22.4, from 22.4 before 22.4R3-S9, from 23.2 before 23.2R2-S6, from 23.4 before 23.4R2-S7, from 24.2 before 24.2R2-S3, from 24.4 before 24.4R2-S3, from 25.2 before 25.2R1-S2, 25.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 21.2R3-S10, 21.4R3-S12, 22.4R3-S9, 23.2R2-S6, 23.4R2-S7, 24.2R2-S3, 24.4R2-S3, 25.2R1-S2, 25.2R2, 25.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS).

When TCP proxy is engaged in a flow session, to support ALGs, Advanced Anti-Malware, ICAP or UTM, a TCP packet with specifically malformed TCP header will cause flow processing daemon (flowd) to crash and restart. This causes a complete service outage until the system has automatically recovered.

This issue affects Junos OS on MX with SPC3, and SRX Series:

23.4 versions before 23.4R2-S7,  24.2 versions before 24.2R2-S4,  24.4 versions before 24.4R2-S3, 25.2 versions before 25.2R2.

This issue does not affect releases before 23.4R1.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203