Where
-Infinity
0
Severity
6.7
Null Pointer Dereference
AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS).

A local high-privileged user configuring or deactivating a specific 'system services ssh' configuration parameter can exploit a null pointer dereference in one of the functions used by SSH. The function attempts to dereference a null pointer when accessing certain configuration data, resulting in an mgd process crash and restart. Continued execution of these configuration commands will create a sustained Denial of Service (DoS) condition.

This issue affects: Junos OS:

from 22.3 before 22.3R3-S5; from 22.4 before 22.4R3-S10; from 23.2 before 23.2R2-S7; from 23.4 before 23.4R2-S8.

This issue does not affect Junos OS before 22.3R1.

Junos OS Evolved: from 22.3R1-EVO before 23.2R2-S7-EVO; from 23.4 before 23.4R2-S8-EVO.

This issue does not affect Junos OS Evolved before 22.3R1-EVO.

First published (updated )
Severity
6.8
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS).

On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted.

This issue affects EX Series, QFX Series, MX Series: Junos OS:

all versions before 23.2R2-S7, 23.4 versions before 23.4R2-S7, 24.2 versions before 24.2R2, 24.4 versions before 24.4R1-S2.

Junos OS Evolved: all versions before 23.2R2-S7-EVO, 23.4 versions before 23.4R2-S8-EVO, 24.2 versions before 24.2R2-EVO, 24.4 versions before 24.4R1-S3-EVO.

First published (updated )
Severity
6.9
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device.

Due to a wrong initialization, a process which should only be able to communicate internally within the device can be reached over the network via an open port. This leads to a device being inadvertently exposed and increased CPU cycles spent processing ingress packets.

This issue affects Junos OS Evolved:

all versions before 23.2R2-S7-EVO, 23.4 versions before 23.4R2-S8-EVO, 24.2 versions before 24.2R2-S5-EVO, 24.4 versions before 24.4R2-S4-EVO, 25.2 versions before 25.2R2-S1-EVO, 25.4 versions before 25.4R1-S2-EVO.

First published (updated )
Severity
7.1
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS).

Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd crash occurs before the update can be readvertised, so there is no downstream propagation.

This issue affects:

Junos OS versions 25.2 before 25.2R2;

Junos OS Evolved versions 25.2 before 25.2R2-EVO.

This issue doesn't affect Junos OS versions before 25.2R1 nor Junos OS Evolved versions before 25.2R1-EVO.

First published (updated )
Severity
6.9
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion.

Due to an incorrect initialization, a process which should only be able to communicate internally within the device, can be reached over the network via an open port. This leads to unauthorized access to the license management.

This issue affects all Junos OS Evolved versions before 23.2R2-EVO.

First published (updated )
Severity
5.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion, resulting in a process crash and restart, impacting the ability to monitor the system via SNMP.

Memory usage can be monitored using the following command:

user@device> show system processes extensive | match snmpd

This issue affects:

Junos OS:

all versions before 21.2R3-S8; from 21.4 before 21.4R3-S7; from 22.1 before 22.1R3-S6; from 22.2 before 22.2R3-S4; from 22.3 before 22.3R3-S3; from 22.4 before 22.4R3-S2; from 23.2 before 23.2R2; from 23.4 before 23.4R2.

Junos OS Evolved: all versions before 21.2R3-S8-EVO; from 21.4 before 21.4R3-S7-EVO; all versions of 22.1-EVO, from 22.2 before 22.2R3-S4-EVO; from 22.3 before 22.3R3-S3-EVO; all versions of 22.4-EVO, from 23.2 before 23.2R2-EVO; from 23.4 before 23.4R2-EVO.

First published (updated )
Severity
7.1
Input Validation
AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS).

An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS:

25.2 versions before 25.2R2

This issue does not affect Junos OS versions before 25.2R1.

This issue affects Junos OS Evolved: 25.2-EVO versions before 25.2R2-EVO

This issue does not affect Junos OS Evolved versions before 25.2R1-EVO.

eBGP and iBGP are affected. IPv4 and IPv6 are affected.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 25.2R2, 25.4R1, and all subsequent releases. Junos OS Evolved: 25.2R2-EVO, 25.4R1-EVO, and all subsequent releases.
First published (updated )
Severity
8.4
OS Command Injection, Command Injection
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete compromise of the system.

Certain 'set system' commands, when executed with crafted arguments, are not properly sanitized, allowing for arbitrary shell injection. These shell commands are executed as root, potentially allowing for complete control of the vulnerable system. This issue affects:

Junos OS:

all versions before 22.4R3-S8,  from 23.2 before 23.2R2-S5,  from 23.4 before 23.4R2-S7,  from 24.2 before 24.2R2-S2,  from 24.4 before 24.4R2,  from 25.2 before 25.2R2;

Junos OS Evolved:

all versions before 22.4R3-S8-EVO,  from 23.2 before 23.2R2-S5-EVO,  from 23.4 before 23.4R2-S7-EVO,  from 24.2 before 24.2R2-S2-EVO,  from 24.4 before 24.4R2-EVO,  from 25.2 before 25.2R1-S1-EVO, 25.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 22.4R3-S8, 23.2R2-S5, 23.4R2-S7, 24.2R2-S2, 24.4R2, 25.2R2, 25.4R1, and all subsequent releases. Junos OS Evolved 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-S7-EVO, 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-S1-EVO, 25.2R2-EVO, 25.4R1-EVO, and all subsequent releases.
First published (updated )
Severity
7.1
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to cause a complete Denial-of-Service (DoS) of the management plane.

When NETCONF sessions are quickly established and disconnected, a locking issue causes mgd processes to hang in an unusable state. When the maximum number of mgd processes has been reached, no new logins are possible. This leads to the inability to manage the device and requires a power-cycle to recover.

This issue can be monitored by checking for mgd processes in lockf state in the output of 'show system processes extensive':

user@host> show system processes extensive | match mgd <pid> root       20   0 501M 4640K lockf   1 0:01 0.00% mgd

If the system still can be accessed (either via the CLI or as root, which might still be possible as last resort as this won't invoke mgd), mgd processes in this state can be killed with 'request system process terminate <PID>' from the CLI or with 'kill -9 <PID>' from the shell.

This issue affects:

Junos OS:

23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2-S1, 24.4 versions before 24.4R1-S3, 24.4R2;

This issue does not affect Junos OS versions before 23.4R1;

Junos OS Evolved:

23.4 versions before 23.4R2-S5-EVO, 24.2 versions before 24.2R2-S1-EVO, 24.4 versions before 24.4R1-S3-EVO, 24.4R2-EVO.

This issue does not affect Junos OS Evolved versions before 23.4R1-EVO;

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 23.4R2-S5-EVO, 24.2R2-S1-EVO, 24.4R1-S3-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases; Junos OS: 23.4R2-S4, 24.2R2-S1, 24.4R1-S3, 24.4R2, 25.2R1, and all subsequent releases.
First published (updated )
Severity
7.1
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultimately leading to a Denial of Service (DoS).

In an EVPN-MPLS scenario, routes learned from remote multi-homed Provider Edge (PE) devices are programmed as ESI routes. Due to a logic issue in the l2ald memory management, memory allocated for these routes is not released when there is churn for these routes. As a result, memory leaks in the l2ald process which will ultimately lead to a crash and restart of l2ald.

Use the following command to monitor the memory consumption by l2ald:

user@device> show system process extensive | match "PID|l2ald"

This issue affects:

Junos OS:

all versions before 22.4R3-S5, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2;

Junos OS Evolved:

all versions before 22.4R3-S5-EVO, 23.2 versions before 23.2R2-S3-EVO, 23.4 versions before 23.4R2-S4-EVO, 24.2 versions before 24.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S5-EVO, 23.2R2-S3-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-EVO, and all subsequent releases; Junos OS: 22.4R3-S5, 23.2R2-S3, 23.4R2-S4, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
6.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user with low privileges to read sensitive information.

A local user with low privileges can execute the CLI command 'show mgd' with specific arguments which will expose sensitive information.

This issue affects

Junos OS: all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S6, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S4, 24.4 versions before 24.4R2-S1, 25.2 version before 25.2R1-S2, 25.2R2;

Junos OS Evolved: all versions before 23.2R2-S6-EVO, 23.4 version before 23.4R2-S6-EVO, 24.2 version before 24.2R2-S4-EVO, 24.4 versions before 24.4R2-S1-EVO, 25.2 versions before 25.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 23.2R2-S6-EVO, 23.4R2-S6-EVO, 24.2R2-S4-EVO, 24.4R2-S1-EVO, 25.2R2-EVO, 25.4R1-EVO, and all subsequent releases; Junos OS: 22.4R3-S8, 23.2R2-S6, 23.4R2-S6, 24.2R2-S4, 24.4R2-S1, 25.2R1-S2, 25.2R2, 25.4R1, and all subsequent releases.
First published (updated )
Severity
8.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system.

When a configuration that allows unsigned Python op scripts is present on the device, a non-root user is able to execute malicious op scripts as a root-equivalent user, leading to privilege escalation.

This issue affects Junos OS:

All versions before 22.4R3-S7,  from 23.2 before 23.2R2-S4,  from 23.4 before 23.4R2-S6, from 24.2 before 24.2R1-S2, 24.2R2,  from 24.4 before 24.4R1-S2, 24.4R2;

Junos OS Evolved:

All versions before 22.4R3-S7-EVO,  from 23.2 before 23.2R2-S4-EVO,  from 23.4 before 23.4R2-S6-EVO, from 24.2 before 24.2R2-EVO,  from 24.4 before 24.4R1-S1-EVO, 24.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S7-EVO, 23.2R2-S4-EVO, 23.4R2-S6-EVO, 24.2R2-EVO, 24.4R1-S1-EVO, 24.4R2-EVO, 25.2R1-EVO and all subsequent releases. Junos OS: 22.4R3-S7, 23.2R2-S4, 23.4R2-S6, 24.2R1-S2, 24.2R2, 24.4R1-S2, 24.4R2, 25.2R1 and all subsequent releases.
First published (updated )
Severity
9.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:Red

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root.

The On-Box Anomaly detection framework should only be reachable by other internal processes over the internal routing instance, but not over an externally exposed port. With the ability to access and manipulate the service to execute code as root a remote attacker can take complete control of the device. Please note that this service is enabled by default as no specific configuration is required.

This issue affects Junos OS Evolved on PTX Series:

25.4 versions before 25.4R1-S1-EVO, 25.4R2-EVO.

This issue does not affect Junos OS Evolved versions before 25.4R1-EVO.

This issue does not affect Junos OS.

Remedy

The following software releases have been updated to resolve this specific issue: 25.4R1-S1-EVO, 25.4R2-EVO*, 26.2R1-EVO*, and all subsequent releases. * Future Release
First published (updated )
Severity
8.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolved allows a local, low-privileged user to gain root privileges, leading to a system compromise.

Any low-privileged user with the capability to send packets over the internal VRF can execute arbitrary Junos commands and modify the configuration, and thus compromise the system.

This issue affects Junos OS Evolved:

All versions before 22.2R3-S7-EVO,  from 22.4 before 22.4R3-S7-EVO,  from 23.2 before 23.2R2-S4-EVO,  from 23.4 before 23.4R2-S5-EVO,  from 24.2 before 24.2R2-S1-EVO from 24.4 before 24.4R1-S2-EVO, 24.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.2R3-S7-EVO, 22.4R3-S7-EVO, 23.2R2-S4-EVO, 23.4R2-S5-EVO, 24.2R2-S1-EVO, 24.4R1-S2-EVO, 24.4R2-EVO, 25.2R1-EVO and all subsequent releases.
First published (updated )
Severity
8.4
OS Command Injection, Command Injection
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a high privileged, local attacker to escalated their privileges to root.

When a user provides specifically crafted arguments to the 'request system logout' command, these will be executed as root on the shell, which can completely compromise the device. This issue affects:

Junos OS:

all versions before 21.2R3-S9, 21.4 versions before 21.4R3-S8, 22.2 versions before 22.2R3-S6, 22.3 versions before 22.3R3-S3, 22.4 versions before 22.4R3-S6, 23.2 versions before 23.2R2-S1, 23.4 versions before 23.4R1-S2, 23.4R2;

Junos OS Evolved:

all versions before 22.4R3-S6-EVO, 23.2-EVO versions before 23.2R2-S1-EVO, 23.4-EVO versions before 23.4R1-S2-EVO, 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S6-EVO, 23.2R2-S1-EVO, 23.4R1-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases; Junos OS: 21.2R3-S9, 21.4R3-S8, 22.2R3-S6, 22.3R3-S3, 22.4R3-S6, 23.2R2-S1, 23.4R1-S2, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )
Severity
5.3
OS Command Injection, Command Injection
AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthorized commands.

When an attacker executes crafted CLI commands, the options are processed via a script in some cases. These scripts are not hardened so injected commands might be executed via the shell, which allows an attacker to perform operations, which they should not be able to do according to their assigned permissions.

This issue affects Junos OS Evolved:

24.2 versions before 24.2R2-S2-EVO, 24.4 versions before 24.4R2-EVO.

This issue does not affect Junos OS Evolved versions earlier than 24.2R1-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases.
First published (updated )
Severity
7.5
EPSS
0.04%
Use After Free
AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

A Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Juniper Networks Junos OS and Junos OS Evolved that could allow an authenticated, network-adjacent attacker flapping a port to crash the dot1xd process, leading to a Denial of Service (DoS), or potentially execute arbitrary code within the context of the process running as root.

The issue is specific to the processing of a change in authorization (CoA) when a port bounce occurs. A pointer is freed but was then referenced later in the same code path. Successful exploitation is outside the attacker's direct control due to the specific timing of the two events required to execute the vulnerable code path.

This issue affects systems with 802.1X authentication port-based network access control (PNAC) enabled. This issue affects:

Junos OS:

from 23.2R2-S1 before 23.2R2-S5,  from 23.4R2 before 23.4R2-S6,  from 24.2 before 24.2R2-S3,  from 24.4 before 24.4R2-S1,  from 25.2 before 25.2R1-S2, 25.2R2;

Junos OS Evolved:

from 23.2R2-S1 before 23.2R2-S5-EVO,  from 23.4R2 before 23.4R2-S6-EVO,  from 24.2 before 24.2R2-S3-EVO,  from 24.4 before 24.4R2-S1-EVO,  from 25.2 before 25.2R1-S2-EVO, 25.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 23.2R2-S5, 23.4R2-S6, 24.2R2-S3, 24.4R2-S1, 25.2R1-S2, 25.2R2, 25.4R1, and all subsequent releases. Junos OS Evolved: 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S3-EVO, 24.4R2-S1-EVO, 25.2R1-S2-EVO, 25.2R2-EVO, 25.4R1-EVO,
First published (updated )
Severity
7.1
EPSS
0.04%
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS).

On devices with SRv6 (Segment Routing over IPv6) enabled, an attacker can send a malformed BGP UPDATE packet which will cause the rpd to crash and restart. Continued receipt of these UPDATE packets will cause a sustained DoS condition.

This issue affects iBGP and eBGP, and both IPv4 and IPv6 are affected by this vulnerability.This issue affects Junos OS:

All versions before 21.2R3-S9,  from 21.4 before 21.4R3-S10,  from 22.2 before 22.2R3-S5,  from 22.3 before 22.3R3-S4,  from 22.4 before 22.4R3-S3,  from 23.2 before 23.2R2-S2,  from 23.4 before 23.4R2;

and Junos OS Evolved:

All versions before 21.2R3-S9-EVO,  from 21.4-EVO before 21.4R3-S10-EVO,  from 22.2-EVO before 22.2R3-S5-EVO,  from 22.3-EVO before 22.3R3-S4-EVO,  from 22.4-EVO before 22.4R3-S3-EVO, from 23.2-EVO before 23.2R2-S2-EVO,  from 23.4-EVO before 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 21.2R3-S9, 21.4R3-S10, 22.2R3-S5, 22.3R3-S4, 22.4R3-S3, 23.2R2-S2, 23.4R2, 24.2R1, and all subsequent releases. Junos OS Evolved: 21.2R3-S9-EVO, 21.4R3-S10-EVO, 22.2R3-S5-EVO, 22.3R3-S4-EVO, 22.4R3-S3-EVO, 23.2R2-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases.
First published (updated )
Severity
7.1
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause an FPC to crash, leading to Denial of Service (DoS).

On all Junos OS and Junos OS Evolved platforms, in an EVPN-VXLAN scenario, when specific ARP packets are received on an IPv4 network, or specific NDP packets are received on an IPv6 network, kernel heap memory leaks, which eventually leads to an FPC crash and restart.

This issue does not affect MX Series platforms. Heap size growth on FPC can be seen using below command.

user@host> show chassis fpc                     Temp CPU Utilization (%) CPU Utilization (%) Memory   Utilization (%) Slot State           (C) Total Interrupt     1min   5min   15min   DRAM (MB)   Heap   Buffer   0 Online           45     3         0       2       2      2       32768      19       0 <<<<<<< Heap increase in all fPCs

This issue affects Junos OS:

All versions before 21.2R3-S7, 21.4 versions before 21.4R3-S4, 22.2 versions before 22.2R3-S1,  22.3 versions before 22.3R3-S1,  22.4 versions before 22.4R2-S2, 22.4R3.

and Junos OS Evolved:

All versions before 21.2R3-S7-EVO, 21.4-EVO versions before 21.4R3-S4-EVO, 22.2-EVO versions before 22.2R3-S1-EVO,  22.3-EVO versions before 22.3R3-S1-EVO,

22.4-EVO versions before 22.4R3-EVO.

Remedy

The following software releases have been updated to resolve this specific issue. Junos OS: 21.2R3-S7, 21.4R3-S4, 22.2R3-S1, 22.3R3-S1, 22.4R2-S2, 22.4R3, 23.2R1, and all subsequent releases. Junos OS Evolved: 21.2R3-S7-EVO, 21.4R3-S4-EVO, 22.2R3-S1-EVO, 22.3R3-S1-EVO, 22.4R3-EVO, 23.2R1-EVO, and all subsequent releases.
First published (updated )
Severity
8.2
EPSS
0.05%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options enabled to crash rpd. This issue affects:

Junos OS:

from 21.2R3-S8 before 21.2R3-S9,  from 21.4R3-S7 before 21.4R3-S9,  from 22.2R3-S4 before 22.2R3-S5,  from 22.3R3-S2 before 22.3R3-S4,  from 22.4R3 before 22.4R3-S5,  from 23.2R2 before 23.2R2-S2,  from 23.4R1 before 23.4R2-S1,  from 24.2R1 before 24.2R1-S1, 24.2R2.

Junos OS Evolved: from 21.4R3-S7-EVO before 21.4R3-S9-EVO,  from 22.2R3-S4-EVO before 22.2R3-S5-EVO,  from 22.3R3-S2-EVO before 22.3R3-S4-EVO,  from 22.4R3-EVO before 22.4R3-S5-EVO,  from 23.2R2-EVO before 23.2R2-S2-EVO,  from 23.4R1-EVO before 23.4R2-S1-EVO,  from 24.2R1-EVO before 24.2R1-S2-EVO, 24.2R2-EVO.

This issue requires a BGP session to be established.

This issue can propagate and multiply through multiple ASes until reaching vulnerable devices.

This issue affects iBGP and eBGP.

This issue affects IPv4 and IPv6.

An indicator of compromise may be the presence of malformed update messages in a neighboring AS which is unaffected by this issue:

For example, by issuing the command on the neighboring device:  show log messages

Reviewing for similar messages from devices within proximity to each other may indicate this malformed packet is propagating:   rpd[<pid>]: Received malformed update from <IP address> (External AS <AS#>) and   rpd[<pid>]: Malformed Attribute

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 21.2R3-S9, 21.4R3-S9, 22.2R3-S5, 22.3R3-S4, 22.4R3-S5, 23.2R2-S2, 23.4R2-S1, 24.2R1-S1, 24.2R2, 24.4R1, and all subsequent releases. Junos OS Evolved: 21.4R3-S9-EVO, 22.2R3-S5-EVO, 22.3R3-S4-EVO, 22.4R3-S5-EVO, 23.2R2-S2-EVO, 23.4R2-S1-EVO, 24.2R1-S2-EVO, 24.2R2-EVO, 24.4R1-EVO, and all subsequent releases.
First published (updated )
Severity
8.7
EPSS
0.05%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Missing Release of Memory after Effective Lifetime vulnerability in the Juniper Tunnel Driver (jtd) of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to cause Denial of Service.

Receipt of specifically malformed IPv6 packets, destined to the device, causes kernel memory to not be freed, resulting in memory exhaustion leading to a system crash and Denial of Service (DoS). Continuous receipt and processing of these packets will continue to exhaust kernel memory, creating a sustained Denial of Service (DoS) condition. This issue only affects systems configured with IPv6.

This issue affects Junos OS Evolved:

from 22.4-EVO before 22.4R3-S5-EVO,  from 23.2-EVO before 23.2R2-S2-EVO,  from 23.4-EVO before 23.4R2-S2-EVO,  from 24.2-EVO before 24.2R1-S2-EVO, 24.2R2-EVO.

This issue does not affect Juniper Networks Junos OS Evolved versions prior to 22.4R1-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S5-EVO, 23.2R2-S2-EVO, 23.4R2-S2-EVO, 24.2R1-S2-EVO, 24.2R2-EVO*, 24.4R1-EVO, and all subsequent releases. * Future Release
First published (updated )
Severity
7.1
EPSS
0.04%
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a specific BGP update packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS).

Continuous receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.

This issue affects iBGP and eBGP, and both IPv4 and IPv6 are affected by this vulnerability.

This issue affects Junos OS:

from 21.4 before 21.4R3-S9,  from 22.2 before 22.2R3-S5,  from 22.3 before 22.3R3-S4, from 22.4 before 22.4R3-S5,  from 23.2 before 23.2R2-S3,  from 23.4 before 23.4R2-S3,  from 24.2 before 24.2R1-S2, 24.2R2;

This issue does not affect versions prior to 21.1R1.

Junos OS Evolved:

from 21.4 before 21.4R3-S9-EVO,  from 22.2 before 22.2R3-S5-EVO,  from 22.3 before 22.3R3-S4-EVO, from 22.4 before 22.4R3-S5-EVO,  from 23.2 before 23.2R2-S3-EVO,  from 23.4 before 23.4R2-S3-EVO,  from 24.2 before 24.2R1-S2-EVO, 24.2R2-EVO.

This issue does not affect versions prior to 21.1R1-EVO

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 21.4R3-S9-EVO, 22.2R3-S5-EVO, 22.3R3-S4-EVO, 22.4R3-S5-EVO, 23.2R2-S3-EVO*, 23.4R2-S3-EVO, 24.2R1-S2-EVO, 24.2R2-EVO*, 24.4R1-EVO, and all subsequent releases. Junos OS: 21.4R3-S9, 22.2R3-S5, 22.3R3-S4, 22.4R3-S5, 23.2R2-S3*, 23.4R2-S3, 24.2R1-S2, 24.2R2*, 24.4R1, and all subsequent releases. * Future Release
First published (updated )
Severity
7.1
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Signed to Unsigned Conversion Error vulnerability in the Layer 2 Control Protocol daemon (l2cpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated adjacent attacker sending a specifically malformed LLDP TLV to cause the l2cpd process to crash and restart, causing a Denial of Service (DoS).  Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.

When an LLDP telemetry subscription is active, receipt of a specifically malformed LLDP TLV causes the l2cpd process to crash and restart.

This issue affects:

Junos OS:

All versions before 21.2R3-S9,  from 21.4 before 21.4R3-S10,  from 22.2 before 22.2R3-S6,  from 22.4 before 22.4R3-S6,  from 23.2 before 23.2R2-S3,  from 23.4 before 23.4R2-S4,  from 24.2 before 24.2R2;

Junos OS Evolved:

All versions before 21.4R3-S10-EVO, from 22.2-EVO before 22.2R3-S6-EVO,  from 22.4-EVO before 22.4R3-S6-EVO,  from 23.2-EVO before 23.2R2-S3-EVO,  from 23.4-EVO before 23.4R2-S4-EVO,  from 24.2-EVO before 24.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue:  Junos OS: 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 23.4R2-S4, 24.2R2, 24.4R1, and all subsequent releases. Junos OS Evolved: 21.4R3-S10-EVO, 22.2R3-S6-EVO, 22.4R3-S6-EVO, 23.2R2-S3-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-EVO, and all subsequent releases.
First published (updated )
Severity
7.4
Input Validation
AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

An Improper Input Validation vulnerability in the Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause the jdhcpd process to crash resulting in a Denial of Service (DoS).

When a specifically malformed DHCP packet is received from a DHCP client, the jdhcpd process crashes, which will lead to the unavailability of the DHCP service and thereby resulting in a sustained DoS. The DHCP process will restart automatically to recover the service.

This issue will occur when dhcp-security is enabled.  This issue affects Junos OS:

All versions before 21.2R3-S9,  from 21.4 before 21.4R3-S10,  from 22.2 before 22.2R3-S6,  from 22.4 before 22.4R3-S6,  from 23.2 before 23.2R2-S3,  from 23.4 before 23.4R2-S4,  from 24.2 before 24.2R2;

Junos OS Evolved:  from 22.4 before 22.4R3-S6-EVO,  from 23.2 before 23.2R2-S3-EVO,  from 23.4 before 23.4R2-S4-EVO,  from 24.2 before 24.2R2-EVO.

.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S6-EVO, 23.2R2-S3-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-EVO, and all subsequent releases. Junos: 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 23.4R2-S4, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
6.9
AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an integrity impact to the downstream devices.

When a peer sends a BGP update message which contains the aggregator attribute with an ASN value of zero (0), rpd accepts and propagates this attribute, which can cause issues for downstream BGP peers receiving this.

This issue affects:

Junos OS:

All versions before 21.4R3-S6, 22.2 versions before 22.2R3-S3, 22.4 versions before 22.4R3;

Junos OS Evolved:

All versions before 21.4R3-S7-EVO, 22.2 versions before 22.2R3-S4-EVO, 22.4 versions before 22.4R3-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 21.4R3-S7-EVO, 22.2R3-S4-EVO, 22.4R3-EVO, 23.2R1-EVO, and all subsequent releases; Junos OS: 21.4R3-S6, 22.1R3-S6, 22.2R3-S3, 22.4R3, 23.2R1, and all subsequent releases.
First published (updated )
Severity
8.7
Double Free
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

This is a similar, but different vulnerability than the issue reported as CVE-2024-39549.

A double-free vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This double free of memory is causing an rpd crash, leading to a Denial of Service (DoS).

This issue affects:

Junos OS:  from 22.4 before 22.4R3-S4.

Junos OS Evolved: from 22.4 before 22.4R3-S4-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 22.4R3-S4 and all subsequent releases. Junos OS Evolved: 22.4R3-S4-EVO and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS).

In specific cases the state of TCP sessions that are terminated is not cleared, which over time leads to an exhaustion of resources, preventing new connections to the control plane from being established.

A continuously increasing number of connections shown by:

user@host > show system connections

is indicative of the problem. To recover the respective RE needs to be restarted manually.

This issue only affects IPv4 but does not affect IPv6. This issue only affects TCP sessions established in-band (over an interface on an FPC) but not out-of-band (over the management ethernet port on the routing-engine).

This issue affects Junos OS Evolved:

All versions before 21.4R3-S9-EVO, 22.2 versions before 22.2R3-S4-EVO, 22.4 version before 22.4R3-S3-EVO, 23.2 versions before 23.2R2-S1-EVO, 23.4 versions before 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: 21.4R3-S9-EVO, 22.2R3-S4-EVO, 22.4R3-S3-EVO, 23.2R2-S1-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS).

In a scenario where BGP Monitoring Protocol (BMP) is configured with rib-in pre-policy monitoring, receiving a BGP update with a specifically malformed AS PATH attribute over an established BGP session, can cause an RPD crash and restart.

This issue affects:

Junos OS:

All versions before 21.2R3-S8, 21.4 versions before 21.4R3-S8, 22.2 versions before 22.2R3-S4, 22.3 versions before 22.3R3-S3, 22.4 versions before 22.4R3-S2, 23.2 versions before 23.2R2-S1, 23.4 versions before 23.4R1-S2, 23.4R2;

Junos OS Evolved:

All versions before 21.2R3-S8-EVO, 21.4 versions before 21.4R3-S8-EVO, 22.2 versions before 22.2R3-S4-EVO, 22.3 versions before 22.3R3-S3-EVO, 22.4 versions before 22.4R3-S2-EVO, 23.2 versions before 23.2R2-S1-EVO, 23.4 versions before 23.4R1-S2-EVO, 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 21.2R3-S8-EVO, 21.4R3-S8-EVO, 22.2R3-S4-EVO, 22.3R3-S3-EVO, 22.4R3-S2-EVO, 23.2R2-S1-EVO, 23.4R1-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases; Junos OS: 21.2R3-S8, 21.4R3-S8, 22.2R3-S4, 22.3R3-S3, 22.4R3-S2, 23.2R2-S1, 23.4R1-S2, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203