An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion.
Due to an incorrect initialization, a process which should only be able to communicate internally within the device, can be reached over the network via an open port. This leads to unauthorized access to the license management.
This issue affects all Junos OS Evolved versions before 23.2R2-EVO.
A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS).
On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted.
This issue affects EX Series, QFX Series, MX Series: Junos OS:
all versions before 23.2R2-S7, 23.4 versions before 23.4R2-S7, 24.2 versions before 24.2R2, 24.4 versions before 24.4R1-S2.
Junos OS Evolved: all versions before 23.2R2-S7-EVO, 23.4 versions before 23.4R2-S8-EVO, 24.2 versions before 24.2R2-EVO, 24.4 versions before 24.4R1-S3-EVO.
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device.
Due to a wrong initialization, a process which should only be able to communicate internally within the device can be reached over the network via an open port. This leads to a device being inadvertently exposed and increased CPU cycles spent processing ingress packets.
This issue affects Junos OS Evolved:
all versions before 23.2R2-S7-EVO, 23.4 versions before 23.4R2-S8-EVO, 24.2 versions before 24.2R2-S5-EVO, 24.4 versions before 24.4R2-S4-EVO, 25.2 versions before 25.2R2-S1-EVO, 25.4 versions before 25.4R1-S2-EVO.
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS).
Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd crash occurs before the update can be readvertised, so there is no downstream propagation.
This issue affects:
Junos OS versions 25.2 before 25.2R2;
Junos OS Evolved versions 25.2 before 25.2R2-EVO.
This issue doesn't affect Junos OS versions before 25.2R1 nor Junos OS Evolved versions before 25.2R1-EVO.
An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion, resulting in a process crash and restart, impacting the ability to monitor the system via SNMP.
Memory usage can be monitored using the following command:
user@device> show system processes extensive | match snmpd
This issue affects:
Junos OS:
all versions before 21.2R3-S8; from 21.4 before 21.4R3-S7; from 22.1 before 22.1R3-S6; from 22.2 before 22.2R3-S4; from 22.3 before 22.3R3-S3; from 22.4 before 22.4R3-S2; from 23.2 before 23.2R2; from 23.4 before 23.4R2.
Junos OS Evolved: all versions before 21.2R3-S8-EVO; from 21.4 before 21.4R3-S7-EVO; all versions of 22.1-EVO, from 22.2 before 22.2R3-S4-EVO; from 22.3 before 22.3R3-S3-EVO; all versions of 22.4-EVO, from 23.2 before 23.2R2-EVO; from 23.4 before 23.4R2-EVO.
A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS).
A local high-privileged user configuring or deactivating a specific 'system services ssh' configuration parameter can exploit a null pointer dereference in one of the functions used by SSH. The function attempts to dereference a null pointer when accessing certain configuration data, resulting in an mgd process crash and restart. Continued execution of these configuration commands will create a sustained Denial of Service (DoS) condition.
This issue affects: Junos OS:
from 22.3 before 22.3R3-S5; from 22.4 before 22.4R3-S10; from 23.2 before 23.2R2-S7; from 23.4 before 23.4R2-S8.
This issue does not affect Junos OS before 22.3R1.
Junos OS Evolved: from 22.3R1-EVO before 23.2R2-S7-EVO; from 23.4 before 23.4R2-S8-EVO.
This issue does not affect Junos OS Evolved before 22.3R1-EVO.
An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete compromise of the system.
Certain 'set system' commands, when executed with crafted arguments, are not properly sanitized, allowing for arbitrary shell injection. These shell commands are executed as root, potentially allowing for complete control of the vulnerable system. This issue affects:
Junos OS:
all versions before 22.4R3-S8, from 23.2 before 23.2R2-S5, from 23.4 before 23.4R2-S7, from 24.2 before 24.2R2-S2, from 24.4 before 24.4R2, from 25.2 before 25.2R2;
Junos OS Evolved:
all versions before 22.4R3-S8-EVO, from 23.2 before 23.2R2-S5-EVO, from 23.4 before 23.4R2-S7-EVO, from 24.2 before 24.2R2-S2-EVO, from 24.4 before 24.4R2-EVO, from 25.2 before 25.2R1-S1-EVO, 25.2R2-EVO.
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user with low privileges to read sensitive information.
A local user with low privileges can execute the CLI command 'show mgd' with specific arguments which will expose sensitive information.
This issue affects
Junos OS: all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S6, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S4, 24.4 versions before 24.4R2-S1, 25.2 version before 25.2R1-S2, 25.2R2;
Junos OS Evolved: all versions before 23.2R2-S6-EVO, 23.4 version before 23.4R2-S6-EVO, 24.2 version before 24.2R2-S4-EVO, 24.4 versions before 24.4R2-S1-EVO, 25.2 versions before 25.2R2-EVO.
An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS).
An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS:
25.2 versions before 25.2R2
This issue does not affect Junos OS versions before 25.2R1.
This issue affects Junos OS Evolved: 25.2-EVO versions before 25.2R2-EVO
This issue does not affect Junos OS Evolved versions before 25.2R1-EVO.
eBGP and iBGP are affected. IPv4 and IPv6 are affected.
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultimately leading to a Denial of Service (DoS).
In an EVPN-MPLS scenario, routes learned from remote multi-homed Provider Edge (PE) devices are programmed as ESI routes. Due to a logic issue in the l2ald memory management, memory allocated for these routes is not released when there is churn for these routes. As a result, memory leaks in the l2ald process which will ultimately lead to a crash and restart of l2ald.
Use the following command to monitor the memory consumption by l2ald:
user@device> show system process extensive | match "PID|l2ald"
This issue affects:
Junos OS:
all versions before 22.4R3-S5, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2;
Junos OS Evolved:
all versions before 22.4R3-S5-EVO, 23.2 versions before 23.2R2-S3-EVO, 23.4 versions before 23.4R2-S4-EVO, 24.2 versions before 24.2R2-EVO.
An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to cause a complete Denial-of-Service (DoS) of the management plane.
When NETCONF sessions are quickly established and disconnected, a locking issue causes mgd processes to hang in an unusable state. When the maximum number of mgd processes has been reached, no new logins are possible. This leads to the inability to manage the device and requires a power-cycle to recover.
This issue can be monitored by checking for mgd processes in lockf state in the output of 'show system processes extensive':
user@host> show system processes extensive | match mgd <pid> root 20 0 501M 4640K lockf 1 0:01 0.00% mgd
If the system still can be accessed (either via the CLI or as root, which might still be possible as last resort as this won't invoke mgd), mgd processes in this state can be killed with 'request system process terminate <PID>' from the CLI or with 'kill -9 <PID>' from the shell.
This issue affects:
Junos OS:
23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2-S1, 24.4 versions before 24.4R1-S3, 24.4R2;
This issue does not affect Junos OS versions before 23.4R1;
Junos OS Evolved:
23.4 versions before 23.4R2-S5-EVO, 24.2 versions before 24.2R2-S1-EVO, 24.4 versions before 24.4R1-S3-EVO, 24.4R2-EVO.
This issue does not affect Junos OS Evolved versions before 23.4R1-EVO;
An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system.
When a configuration that allows unsigned Python op scripts is present on the device, a non-root user is able to execute malicious op scripts as a root-equivalent user, leading to privilege escalation.
This issue affects Junos OS:
All versions before 22.4R3-S7, from 23.2 before 23.2R2-S4, from 23.4 before 23.4R2-S6, from 24.2 before 24.2R1-S2, 24.2R2, from 24.4 before 24.4R1-S2, 24.4R2;
Junos OS Evolved:
All versions before 22.4R3-S7-EVO, from 23.2 before 23.2R2-S4-EVO, from 23.4 before 23.4R2-S6-EVO, from 24.2 before 24.2R2-EVO, from 24.4 before 24.4R1-S1-EVO, 24.4R2-EVO.
An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root.
The On-Box Anomaly detection framework should only be reachable by other internal processes over the internal routing instance, but not over an externally exposed port. With the ability to access and manipulate the service to execute code as root a remote attacker can take complete control of the device. Please note that this service is enabled by default as no specific configuration is required.
This issue affects Junos OS Evolved on PTX Series:
25.4 versions before 25.4R1-S1-EVO, 25.4R2-EVO.
This issue does not affect Junos OS Evolved versions before 25.4R1-EVO.
This issue does not affect Junos OS.
A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker authenticated with low privileges to cause a Denial-of-Service (DoS).
When telemetry collectors are frequently subscribing and unsubscribing to sensors continuously over a long period of time, telemetry-capable processes like chassisd, rpd or mib2d will crash and restart, which - depending on the process - can cause a complete outage until the system has recovered.
This issue affects:
Junos OS:
all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S5, 23.4 versions before 23.4R2;
Junos OS Evolved:
all versions before 22.4R3-S8-EVO, 23.2 versions before 23.2R2-S5-EVO, 23.4 versions before 23.4R2-EVO.
An Incorrect Calculation vulnerability in the Layer 2 Control
Protocol
Daemon (l2cpd) of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker flapping the management interface to cause the learning of new MACs over label-switched interfaces (LSI) to stop while generating a flood of logs, resulting in high CPU usage.
When the issue is seen, the following log message will be generated:
op:1 flag:0x6 mac:xx:xx:xx:xx:xx:xx bd:2 ifl:13302 reason:0(REASONNONE) i-op:6(INTRNLOPHWFORCEDELETE) status:10 lstatus:10 err:26(GETIFBDVALIDATEFAILED) err-reason 4(IFBDVALIDATEFAILEPOCHMISMATCH) hwwr:0x4 ctxsync:0 fwdsync:0 rtt-id:51 pifl:0 fwdnh:0 svlbnh:0 event:- smask:0x100000000 dmask:0x0 mplsmask 0x1 act:0x5800 extf:0x0 pfe-id 0 hw-notif-ifl 13302 programmed-ifl 4294967295 pseudo-vtep underlay-ifl-idx 0 stack:GETMAC, ALLOCATEMAC, GETIFL, GETIFF, GETIFBD, STOP,
This issue affects Junos OS Evolved:
all versions before 21.4R3-S7-EVO, from 22.2 before 22.2R3-S4-EVO, from 22.3 before 22.3R3-S3-EVO, from 22.4 before 22.4R3-S2-EVO, from 23.2 before 23.2R2-S1-EVO, from 23.4 before 23.4R1-S2-EVO, 23.4R2-EVO.
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send a specific update packet causing a memory leak. Continued receipt and processing of these packets will exhaust all available memory, crashing rpd and creating a Denial of Service (DoS) condition.
Memory usage can be monitored through the use of the 'show task memory detail' command. For example:
user@junos> show task memory detail | match ted-infra TED-INFRA-COOKIE 25 1072 28 1184 229
user@junos>
show task memory detail | match ted-infra TED-INFRA-COOKIE 31 1360 34 1472 307
This issue affects:
Junos OS:
from 23.2 before 23.2R2, from 23.4 before 23.4R1-S2, 23.4R2, from 24.1 before 24.1R2;
Junos OS Evolved:
from 23.2 before 23.2R2-EVO, from 23.4 before 23.4R1-S2-EVO, 23.4R2-EVO, from 24.1 before 24.1R2-EVO.
This issue does not affect Junos OS versions before 23.2R1 or Junos OS Evolved versions before 23.2R1-EVO.
A Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Juniper Networks Junos OS and Junos OS Evolved that could allow an authenticated, network-adjacent attacker flapping a port to crash the dot1xd process, leading to a Denial of Service (DoS), or potentially execute arbitrary code within the context of the process running as root.
The issue is specific to the processing of a change in authorization (CoA) when a port bounce occurs. A pointer is freed but was then referenced later in the same code path. Successful exploitation is outside the attacker's direct control due to the specific timing of the two events required to execute the vulnerable code path.
This issue affects systems with 802.1X authentication port-based network access control (PNAC) enabled. This issue affects:
Junos OS:
from 23.2R2-S1 before 23.2R2-S5, from 23.4R2 before 23.4R2-S6, from 24.2 before 24.2R2-S3, from 24.4 before 24.4R2-S1, from 25.2 before 25.2R1-S2, 25.2R2;
Junos OS Evolved:
from 23.2R2-S1 before 23.2R2-S5-EVO, from 23.4R2 before 23.4R2-S6-EVO, from 24.2 before 24.2R2-S3-EVO, from 24.4 before 24.4R2-S1-EVO, from 25.2 before 25.2R1-S2-EVO, 25.2R2-EVO.
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an availability impact for downstream devices.
When an affected device receives a specific optional, transitive BGP attribute over an existing BGP session, it will be erroneously modified before propagation to peers. When the attribute is detected as malformed by the peers, these peers will most likely terminate the BGP sessions with the affected devices and thereby cause an availability impact due to the resulting routing churn.
This issue affects:
Junos OS:
all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S5 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S2, 24.4 versions before 24.4R2;
Junos OS Evolved:
all versions before 22.4R3-S8-EVO, 23.2 versions before 23.2R2-S5-EVO, 23.4 versions before 23.4R2-S6-EVO, 24.2 versions before 24.2R2-S2-EVO, 24.4 versions before 24.4R2-EVO.
A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
When an affected device receives a BGP update with a set of specific optional transitive attributes over an established peering session, rpd will crash and restart when attempting to advertise the received information to another peer. This issue can only happen if one or both of the BGP peers of the receiving session are non-4-byte-AS capable as determined from the advertised capabilities during BGP session establishment. Junos OS and Junos OS Evolved default behavior is 4-byte-AS capable unless this has been specifically disabled by configuring:
[ protocols bgp ... disable-4byte-as ]
Established BGP sessions can be checked by executing:
show bgp neighbor <IP address> | match "4 byte AS"
This issue affects:
Junos OS:
all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S5, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S2, 24.4 versions before 24.4R2;
Junos OS Evolved:
all versions before 22.4R3-S8-EVO, 23.2 versions before 23.2R2-S5-EVO, 23.4 versions before 23.4R2-S6-EVO, 24.2 versions before 24.2R2-S2-EVO, 24.4 versions before 24.4R2-EVO.
An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to write to the Unix socket used to manage the jdhcpd process, resulting in complete control over the resource.
This vulnerability allows any low-privileged user logged into the system to connect to the Unix socket and issue commands to manage the DHCP service, in essence, taking administrative control of the local DHCP server or DHCP relay.
This issue affects: Junos OS: all versions before 21.2R3-S10, all versions of 22.2, from 21.4 before 21.4R3-S12, from 22.4 before 22.4R3-S8, from 23.2 before 23.2R2-S5, from 23.4 before 23.4R2-S6, from 24.2 before 24.2R2-S2, from 24.4 before 24.4R2, from 25.2 before 25.2R1-S1, 25.2R2;
Junos OS Evolved: all versions before 22.4R3-S8-EVO, from 23.2 before 23.2R2-S5-EVO, from 23.4 before 23.4R2-S6-EVO, from 24.2 before 24.2R2-S2-EVO, from 24.4 before 24.4R2-EVO, from 25.2 before 25.2R1-S1-EVO, 25.2R2-EVO.
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a DHCP client in one subnet to exhaust the address pools of other subnets, leading to a Denial of Service (DoS) on the downstream DHCP server.
By default, the DHCP relay agent inserts its own Option 82 information when forwarding client requests, optionally replacing any Option 82 information provided by the client. When a specific DHCP DISCOVER is received in 'forward-only' mode with Option 82, the device should drop the message unless 'trust-option82' is configured. Instead, the DHCP relay forwards these packets to the DHCP server unmodified, which uses up addresses in the DHCP server's address pool, ultimately leading to address pool exhaustion.
This issue affects Junos OS:
all versions before 21.2R3-S10, from 21.4 before 21.4R3-S12, all versions of 22.2, from 22.4 before 22.4R3-S8, from 23.2 before 23.2R2-S5, from 23.4 before 23.4R2-S6, from 24.2 before 24.2R2-S2, from 24.4 before 24.4R2, from 25.2 before 25.2R1-S1, 25.2R2.
Junos OS Evolved:
all versions before 21.4R3-S12-EVO, all versions of 22.2-EVO, from 22.4 before 22.4R3-S8-EVO, from 23.2 before 23.2R2-S5-EVO, from 23.4 before 23.4R2-S6-EVO, from 24.2 before 24.2R2-S2-EVO, from 24.4 before 24.4R2-EVO, from 25.2 before 25.2R1-S1-EVO, 25.2R2-EVO.
An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS).
When the command 'show route < ( receive-protocol | advertising-protocol ) bgp > detail' is executed, and at least one of the routes in the intended output has specific attributes, this will cause an rpd crash and restart. 'show route ... extensive' is not affected.
This issue affects:
Junos OS:
all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S5, 23.4 versions before 23.4R2-S5, 24.2 versions before 24.2R2-S2, 24.4 versions before 24.4R2;
Junos OS Evolved:
all versions before 22.4R3-S8-EVO, 23.2 versions before 23.2R2-S5-EVO, 23.4 versions before 23.4R2-S6-EVO, 24.2 versions before 24.2R2-S2-EVO, 24.4 versions before 24.4R2-EVO.
A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the device without enforcing the required password change.
Affected devices allow logins by users for whom the RADIUS server has responded with a reject and required the user to change the password as their password was expired. Therefore the policy mandating the password change is not enforced. This does not allow users to login with a wrong password, but only with the correct but expired one.
This issue affects:
Junos OS:
all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S4, 23.4 versions before 23.4R2-S5, 24.2 versions before 24.2R2-S1, 24.4 versions before 24.4R1-S3, 24.4R2;
Junos OS Evolved:
all versions before 22.4R3-S8-EVO, 23.2 versions before 23.2R2-S4-EVO, 23.4 versions before 23.4R2-S5-EVO, 24.2 versions before 24.2R2-S1-EVO, 24.4 versions before 24.4R1-S3-EVO, 24.4R2-EVO.
Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthorized commands.
When an attacker executes crafted CLI commands, the options are processed via a script in some cases. These scripts are not hardened so injected commands might be executed via the shell, which allows an attacker to perform operations, which they should not be able to do according to their assigned permissions.
This issue affects Junos OS Evolved:
24.2 versions before 24.2R2-S2-EVO, 24.4 versions before 24.4R2-EVO.
This issue does not affect Junos OS Evolved versions earlier than 24.2R1-EVO.
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS).
When an affected system receives a specific BGP EVPN update message over an established BGP session, this causes an rpd crash and restart.
A BGP EVPN configuration is not necessary to be vulnerable. If peers are not configured to send BGP EVPN updates to a vulnerable device, then this issue can't occur.
This issue affects iBGP and eBGP, over IPv4 and IPv6.
This issue affects: Junos OS: 23.4 versions from
23.4R2-S3 before 23.4R2-S5, 24.2 versions from
24.2R2
before 24.2R2-S1, 24.4 versions before 24.4R1-S3, 24.4R2;
Junos OS Evolved: 23.4-EVO versions from 23.4R2-S2-EVO before 23.4R2-S5-EVO, 24.2-EVO versions from 24.2R2-EVO before 24.2R2-S1-EVO, 24.4-EVO versions before 24.4R1-S3-EVO, 24.4R2-EVO.
A NULL Pointer Dereference vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved on ACX7024, ACX7024X, ACX7100-32C, ACX7100-48L, ACX7348, ACX7509 devices allows an unauthenticated, adjacent attacker to cause a
Denial-of-Service (DoS).
Whenever specific valid multicast traffic is received on any layer 3 interface the evo-pfemand process crashes and restarts.
Continued receipt of specific valid multicast traffic results in a sustained Denial of Service (DoS) attack. This issue affects Junos OS Evolved on ACX7024, ACX7024X, ACX7100-32C, ACX7100-48L, ACX7348, ACX7509:
from 23.2R2-EVO before 23.2R2-S4-EVO, from 23.4R1-EVO before 23.4R2-EVO.
This issue affects IPv4 and IPv6.
This issue does not affect Junos OS Evolved ACX7024, ACX7024X, ACX7100-32C, ACX7100-48L, ACX7348, ACX7509 versions before 23.2R2-EVO.
An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved with BGP sharding configured allows an attacker triggering indirect next-hop updates, along with timing outside the attacker's control, to cause rpd to crash and restart, leading to a Denial of Service (DoS).
With BGP sharding enabled, triggering route resolution of an indirect next-hop (e.g., an IGP route change over which a BGP route gets resolved), may cause rpd to crash and restart. An attacker causing continuous IGP route churn, resulting in repeated route re-resolution, will increase the likelihood of triggering this issue, leading to a potentially extended DoS condition.
This issue affects:
Junos OS:
all versions before 21.4R3-S6, from 22.1 before 22.1R3-S6, from 22.2 before 22.2R3-S3, from 22.3 before 22.3R3-S3, from 22.4 before 22.4R3, from 23.2 before 23.2R2;
Junos OS Evolved:
all versions before 22.3R3-S3-EVO, from 22.4 before 22.4R3-EVO, from 23.2 before 23.2R2-EVO.
Versions before Junos OS 21.3R1 and Junos OS Evolved 21.3R1-EVO are unaffected by this issue.
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to cause impact to confidentiality and availability.
When an output firewall filter is configured with one or more terms where the action is 'reject', packets matching these terms are erroneously sent to the Routing Engine (RE) and further processed there. Processing of these packets will consume limited RE resources. Also responses from the RE back to the source of this traffic could reveal confidential information about the affected device. This issue only applies to firewall filters applied to WAN or revenue interfaces, so not the mgmt or lo0 interface of the routing-engine, nor any input filters.
This issue affects Junos OS Evolved on PTX Series:
all versions before 22.4R3-EVO, 23.2 versions before 23.2R2-EVO.