Where
AND
-Infinity
0
Severity
7.1
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS).

Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd crash occurs before the update can be readvertised, so there is no downstream propagation.

This issue affects:

Junos OS versions 25.2 before 25.2R2;

Junos OS Evolved versions 25.2 before 25.2R2-EVO.

This issue doesn't affect Junos OS versions before 25.2R1 nor Junos OS Evolved versions before 25.2R1-EVO.

First published (updated )
Severity
8.4
OS Command Injection, Command Injection
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete compromise of the system.

Certain 'set system' commands, when executed with crafted arguments, are not properly sanitized, allowing for arbitrary shell injection. These shell commands are executed as root, potentially allowing for complete control of the vulnerable system. This issue affects:

Junos OS:

all versions before 22.4R3-S8,  from 23.2 before 23.2R2-S5,  from 23.4 before 23.4R2-S7,  from 24.2 before 24.2R2-S2,  from 24.4 before 24.4R2,  from 25.2 before 25.2R2;

Junos OS Evolved:

all versions before 22.4R3-S8-EVO,  from 23.2 before 23.2R2-S5-EVO,  from 23.4 before 23.4R2-S7-EVO,  from 24.2 before 24.2R2-S2-EVO,  from 24.4 before 24.4R2-EVO,  from 25.2 before 25.2R1-S1-EVO, 25.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 22.4R3-S8, 23.2R2-S5, 23.4R2-S7, 24.2R2-S2, 24.4R2, 25.2R2, 25.4R1, and all subsequent releases. Junos OS Evolved 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-S7-EVO, 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-S1-EVO, 25.2R2-EVO, 25.4R1-EVO, and all subsequent releases.
First published (updated )
Severity
7.1
Input Validation
AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS).

An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS:

25.2 versions before 25.2R2

This issue does not affect Junos OS versions before 25.2R1.

This issue affects Junos OS Evolved: 25.2-EVO versions before 25.2R2-EVO

This issue does not affect Junos OS Evolved versions before 25.2R1-EVO.

eBGP and iBGP are affected. IPv4 and IPv6 are affected.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 25.2R2, 25.4R1, and all subsequent releases. Junos OS Evolved: 25.2R2-EVO, 25.4R1-EVO, and all subsequent releases.
First published (updated )
Severity
7.1
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultimately leading to a Denial of Service (DoS).

In an EVPN-MPLS scenario, routes learned from remote multi-homed Provider Edge (PE) devices are programmed as ESI routes. Due to a logic issue in the l2ald memory management, memory allocated for these routes is not released when there is churn for these routes. As a result, memory leaks in the l2ald process which will ultimately lead to a crash and restart of l2ald.

Use the following command to monitor the memory consumption by l2ald:

user@device> show system process extensive | match "PID|l2ald"

This issue affects:

Junos OS:

all versions before 22.4R3-S5, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2;

Junos OS Evolved:

all versions before 22.4R3-S5-EVO, 23.2 versions before 23.2R2-S3-EVO, 23.4 versions before 23.4R2-S4-EVO, 24.2 versions before 24.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S5-EVO, 23.2R2-S3-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-EVO, and all subsequent releases; Junos OS: 22.4R3-S5, 23.2R2-S3, 23.4R2-S4, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
7
AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root which will lead to a complete compromise of the system.

When after a user has performed a specific 'file link ...' CLI operation, another user commits (unrelated configuration changes), the first user can login as root.

This issue affects Junos OS: all versions before 23.2R2-S7, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S3, 24.4 versions before 24.4R2-S2, 25.2 versions before 25.2R2.

This issue does not affect versions 25.4R1 or later.

Remedy

The following software releases have been updated to resolve this specific issue: 23.2R2-S7, 23.4R2-S6, 24.2R2-S3, 24.4R2-S2, 25.2R2, and all subsequent releases.
First published (updated )
Severity
7.1
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to cause a complete Denial-of-Service (DoS) of the management plane.

When NETCONF sessions are quickly established and disconnected, a locking issue causes mgd processes to hang in an unusable state. When the maximum number of mgd processes has been reached, no new logins are possible. This leads to the inability to manage the device and requires a power-cycle to recover.

This issue can be monitored by checking for mgd processes in lockf state in the output of 'show system processes extensive':

user@host> show system processes extensive | match mgd <pid> root       20   0 501M 4640K lockf   1 0:01 0.00% mgd

If the system still can be accessed (either via the CLI or as root, which might still be possible as last resort as this won't invoke mgd), mgd processes in this state can be killed with 'request system process terminate <PID>' from the CLI or with 'kill -9 <PID>' from the shell.

This issue affects:

Junos OS:

23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2-S1, 24.4 versions before 24.4R1-S3, 24.4R2;

This issue does not affect Junos OS versions before 23.4R1;

Junos OS Evolved:

23.4 versions before 23.4R2-S5-EVO, 24.2 versions before 24.2R2-S1-EVO, 24.4 versions before 24.4R1-S3-EVO, 24.4R2-EVO.

This issue does not affect Junos OS Evolved versions before 23.4R1-EVO;

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 23.4R2-S5-EVO, 24.2R2-S1-EVO, 24.4R1-S3-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases; Junos OS: 23.4R2-S4, 24.2R2-S1, 24.4R1-S3, 24.4R2, 25.2R1, and all subsequent releases.
First published (updated )
Severity
8.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system.

When a configuration that allows unsigned Python op scripts is present on the device, a non-root user is able to execute malicious op scripts as a root-equivalent user, leading to privilege escalation.

This issue affects Junos OS:

All versions before 22.4R3-S7,  from 23.2 before 23.2R2-S4,  from 23.4 before 23.4R2-S6, from 24.2 before 24.2R1-S2, 24.2R2,  from 24.4 before 24.4R1-S2, 24.4R2;

Junos OS Evolved:

All versions before 22.4R3-S7-EVO,  from 23.2 before 23.2R2-S4-EVO,  from 23.4 before 23.4R2-S6-EVO, from 24.2 before 24.2R2-EVO,  from 24.4 before 24.4R1-S1-EVO, 24.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S7-EVO, 23.2R2-S4-EVO, 23.4R2-S6-EVO, 24.2R2-EVO, 24.4R1-S1-EVO, 24.4R2-EVO, 25.2R1-EVO and all subsequent releases. Junos OS: 22.4R3-S7, 23.2R2-S4, 23.4R2-S6, 24.2R1-S2, 24.2R2, 24.4R1-S2, 24.4R2, 25.2R1 and all subsequent releases.
First published (updated )
Severity
8.4
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root.

This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include: MPC7, MPC8, MPC9, MPC10, MPC11 LC2101, LC2103 LC480, LC4800, LC9600 MX304 (built-in FPC) MX-SPC3 SRX5K-SPC3 EX9200-40XS

FPC3-PTX-U2, FPC3-PTX-U3 FPC3-SFF-PTX LC1101, LC1102, LC1104, LC1105

This issue affects Junos OS:

all versions before 22.4R3-S8,  from 23.2 before 23.2R2-S6,  from 23.4 before 23.4R2-S6,  from 24.2 before 24.2R2-S3,  from 24.4 before 24.4R2, from 25.2 before 25.2R2.

First published (updated )
Severity
7.1
EPSS
0.04%
Use After Free
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker authenticated with low privileges to cause a Denial-of-Service (DoS).

When telemetry collectors are frequently subscribing and unsubscribing to sensors continuously over a long period of time, telemetry-capable processes like chassisd, rpd or mib2d will crash and restart, which - depending on the process - can cause a complete outage until the system has recovered.

This issue affects:

Junos OS:

all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S5, 23.4 versions before 23.4R2;

Junos OS Evolved:

all versions before 22.4R3-S8-EVO, 23.2 versions before 23.2R2-S5-EVO, 23.4 versions before 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases; Junos OS: 22.4R3-S8, 23.2R2-S5, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )
Severity
8.7
EPSS
0.05%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

If an SRX Series device configured for DNS processing, receives a specifically formatted DNS request flowd will crash and restart, which causes a service interruption until the process has recovered.

This issue affects Junos OS on SRX Series:

23.4 versions before 23.4R2-S5, 24.2 versions before 24.2R2-S1, 24.4 versions before 24.4R2.

This issue does not affect Junos OS versions before 23.4R1.

Remedy

The following software releases have been updated to resolve this specific issue: 23.4R2-S5, 24.2R2-S1, 24.4R2, 24.4R2-S1, 25.2R1, and all subsequent releases.
First published (updated )
Severity
8.7
EPSS
0.05%
Double Free
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX and MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX and MX Series platforms, when during TCP session establishment a specific sequence of packets is encountered a double free happens. This causes flowd to crash and the respective FPC to restart.

This issue affects Junos OS on SRX and MX Series:

all versions before 22.4R3-S7, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: 22.4R3-S7, 23.2R2-S3, 23.4R2-S4, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
EPSS
0.12%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

If an SRX device configured for UTM Web-Filtering receives a specifically malformed SSL packet, this will cause an FPC crash and restart. This issue affects Junos OS on SRX Series:

23.2 versions from 23.2R2-S2 before 23.2R2-S5,  23.4 versions from 23.4R2-S1 before 23.4R2-S5, 24.2 versions before 24.2R2-S2, 24.4 versions before 24.4R1-S3, 24.4R2.

Earlier versions of Junos are also affected, but no fix is available.

Remedy

The following software releases have been updated to resolve this specific issue: 23.2R2-S5, 23.4R2-S5, 24.2R2-S2, 24.4R1-S3, 24.4R2, 25.2R1, and all subsequent releases.
First published (updated )
Severity
8.7
EPSS
0.04%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos).

If an SRX Series device receives a specifically malformed GPRS Tunnelling Protocol (GTP) Modify Bearer Request message, a lock is acquired and never released. This results in other threads not being able to acquire a lock themselves, causing a watchdog timeout leading to FPC crash and restart. This issue leads to a complete traffic outage until the device has automatically recovered.

This issue affects Junos OS on SRX Series:

all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S5, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S3, 24.4 versions before 24.4R2-S2, 25.2 versions before 25.2R1-S1, 25.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S3, 24.4R2-S2, 25.2R1-S1, 25.2R2, 25.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
EPSS
0.05%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on EX4000 models allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

On EX4000 models with 48 ports (EX4000-48T, EX4000-48P, EX4000-48MP) a high volume of traffic destined to the device will cause an FXPC crash and restart, which leads to a complete service outage until the device has automatically restarted.

The following reboot reason can be seen in the output of 'show chassis routing-engine' and as a log message:

reason=0x4000002 reasonstring=0x4000002:watchdog + panic with core dump

This issue affects Junos OS on EX4000-48T, EX4000-48P and EX4000-48MP:

24.4 versions before 24.4R2, 25.2 versions before 25.2R1-S2, 25.2R2.

This issue does not affect versions before 24.4R1 as the first Junos OS version for the EX4000 models was 24.4R1.

Remedy

The following software releases have been updated to resolve this specific issue: 24.4R2, 25.2R1-S2, 25.2R2, 25.4R1, and all subsequent releases.
First published (updated )
Severity
7.1
EPSS
0.02%
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on EX4k Series and QFX5k Series platforms allows an unauthenticated network-adjacent attacker flapping an interface to cause traffic between VXLAN Network Identifiers (VNIs) to drop, leading to a Denial of Service (DoS).

On all EX4k and QFX5k platforms, a link flap in an

EVPN-VXLAN configuration Link Aggregation Group (LAG) results in Inter-VNI traffic dropping when there are multiple load-balanced next-hop routes for the same destination.

This issue is only applicable to systems that support EVPN-VXLAN Virtual Port-Link Aggregation Groups (VPLAG), such as the QFX5110, QFX5120, QFX5200, EX4100, EX4300, EX4400, and EX4650.

Service can only be restored by restarting the affected FPC via the 'request chassis fpc restart slot <slot-number>' command.

This issue affects Junos OS

on EX4k and QFX5k Series:

all versions before 21.4R3-S12,  all versions of 22.2 from 22.4 before 22.4R3-S8,  from 23.2 before 23.2R2-S5,  from 23.4 before 23.4R2-S5,  from 24.2 before 24.2R2-S3, from 24.4 before 24.4R2.

First published (updated )
Severity
7.1
EPSS
0.02%
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send a specific update packet causing a memory leak. Continued receipt and processing of these packets will exhaust all available memory, crashing rpd and creating a Denial of Service (DoS) condition.

Memory usage can be monitored through the use of the 'show task memory detail' command. For example:

user@junos> show task memory detail | match ted-infra   TED-INFRA-COOKIE           25   1072     28   1184     229

user@junos>

show task memory detail | match ted-infra   TED-INFRA-COOKIE           31   1360     34   1472     307

This issue affects:

Junos OS:

from 23.2 before 23.2R2,  from 23.4 before 23.4R1-S2, 23.4R2,  from 24.1 before 24.1R2;

Junos OS Evolved:

from 23.2 before 23.2R2-EVO,  from 23.4 before 23.4R1-S2-EVO, 23.4R2-EVO,  from 24.1 before 24.1R2-EVO.

This issue does not affect Junos OS versions before 23.2R1 or Junos OS Evolved versions before 23.2R1-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2, 23.4R1-S2, 23.4R2, 24.1R2, 24.2R1, and all subsequent releases. Junos OS Evolved: 23.2R2-EVO, 23.4R1-S2-EVO, 23.4R2-EVO, 24.1R2-EVO, 24.2R1-EVO, and all subsequent releases.
First published (updated )
Severity
7.5
EPSS
0.04%
Use After Free
AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

A Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Juniper Networks Junos OS and Junos OS Evolved that could allow an authenticated, network-adjacent attacker flapping a port to crash the dot1xd process, leading to a Denial of Service (DoS), or potentially execute arbitrary code within the context of the process running as root.

The issue is specific to the processing of a change in authorization (CoA) when a port bounce occurs. A pointer is freed but was then referenced later in the same code path. Successful exploitation is outside the attacker's direct control due to the specific timing of the two events required to execute the vulnerable code path.

This issue affects systems with 802.1X authentication port-based network access control (PNAC) enabled. This issue affects:

Junos OS:

from 23.2R2-S1 before 23.2R2-S5,  from 23.4R2 before 23.4R2-S6,  from 24.2 before 24.2R2-S3,  from 24.4 before 24.4R2-S1,  from 25.2 before 25.2R1-S2, 25.2R2;

Junos OS Evolved:

from 23.2R2-S1 before 23.2R2-S5-EVO,  from 23.4R2 before 23.4R2-S6-EVO,  from 24.2 before 24.2R2-S3-EVO,  from 24.4 before 24.4R2-S1-EVO,  from 25.2 before 25.2R1-S2-EVO, 25.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 23.2R2-S5, 23.4R2-S6, 24.2R2-S3, 24.4R2-S1, 25.2R1-S2, 25.2R2, 25.4R1, and all subsequent releases. Junos OS Evolved: 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S3-EVO, 24.4R2-S1-EVO, 25.2R1-S2-EVO, 25.2R2-EVO, 25.4R1-EVO,
First published (updated )
Severity
8.7
EPSS
0.05%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated network-based attacker sending a specific ICMP packet through a GRE tunnel to cause the PFE to crash and restart.

When PowerMode IPsec (PMI) and GRE performance acceleration are enabled and the device receives a specific ICMP packet, a crash occurs in the SRX PFE, resulting in traffic loss. PMI is enabled by default, and GRE performance acceleration can be enabled by running the configuration command shown below. PMI is a mode of operation that provides IPsec performance improvements using Vector Packet Processing.

Note that PMI with GRE performance acceleration is only supported on specific SRX platforms. This issue affects Junos OS on the SRX Series:

all versions before 21.4R3-S12,  from 22.4 before 22.4R3-S8,  from 23.2 before 23.2R2-S5,  from 23.4 before 23.4R2-S5,  from 24.2 before 24.2R2-S3,  from 24.4 before 24.4R2-S1,  from 25.2 before 25.2R1-S1, 25.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 21.4R3-S12, 22.4R3-S8, 23.2R2-S5, 23.4R2-S5, 24.2R2-S3, 24.4R2-S1, 25.2R1-S1, 25.2R2, 25.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
EPSS
0.05%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-SPC3 or MS-MPC allows an unauthenticated network-based attacker sending specific SIP messages over TCP to crash the flow management process, leading to a Denial of Service (DoS).

On SRX Series, and MX Series with MX-SPC3 or MS-MPC service cards, receipt of multiple SIP messages causes the SIP headers to be parsed incorrectly, eventually causing a continuous loop and leading to a watchdog timer expiration, crashing the flowd process on SRX Series and MX Series with MX-SPC3, or mspmand process on MX Series with MS-MPC.

This issue only occurs over TCP. SIP messages sent over UDP cannot trigger this issue.

This issue affects Junos OS on SRX Series and MX Series with MX-SPC3 and MS-MPC:

all versions before 21.2R3-S10,  from 21.4 before 21.4R3-S12,  from 22.4 before 22.4R3-S8,  from 23.2 before 23.2R2-S5,  from 23.4 before 23.4R2-S6,  from 24.2 before 24.2R2-S3,  from 24.4 before 24.4R2-S1,  from 25.2 before 25.2R1-S1, 25.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: 21.2R3-S10, 21.4R3-S12, 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S3, 24.4R2-S1, 25.2R1-S1, 25.2R2, 25.4R1, and all subsequent releases.
First published (updated )
Severity
7.1
EPSS
0.04%
Buffer Overflow
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a network-based attacker, authenticated with low privileges to cause a Denial-of-Service (DoS).

Subscribing to telemetry sensors at scale causes all FPC connections to drop, resulting in an FPC crash and restart. The issue was not seen when YANG packages for the specific sensors were installed.

This issue affects Junos OS:

all versions before 22.4R3-S7, 23.2 version before 23.2R2-S4, 23.4 versions before 23.4R2.

Remedy

The following software releases have been updated to resolve this specific issue: 22.4R3-S7, 23.2R2-S4, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )
Severity
7.1
EPSS
0.02%
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an unauthenticated, network-adjacent attacker sending a specifically malformed ICMP packet to cause an FPC to crash and restart, resulting in a Denial of Service (DoS).

When an ICMP packet is received with a specifically malformed IP header value, the FPC receiving the packet crashes and restarts. Due to the specific type of malformed packet, adjacent upstream routers would not forward the packet, limiting the attack surface to adjacent networks.

This issue only affects ICMPv4. ICMPv6 is not vulnerable to this issue.

This issue does not affect AFT-based line cards such as the MPC10, MPC11, LC4800, LC9600, and MX304.

This issue affects Junos OS:

all versions before 21.2R3-S9,  from 21.4 before 21.4R3-S10,  from 22.2 before 22.2R3-S7,  from 22.3 before 22.3R3-S4,  from 22.4 before 22.4R3-S5,  from 23.2 before 23.2R2-S3,  from 23.4 before 23.4R2-S3,  from 24.2 before 24.2R1-S2, 24.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 20.2R3-S10, 21.2R3-S9, 21.4R3-S10, 22.2R3-S7, 22.3R3-S4, 22.4R3-S5, 23.2R2-S3, 23.4R2-S3, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

When an affected device receives a BGP update with a set of specific optional transitive attributes over an established peering session, rpd will crash and restart when attempting to advertise the received information to another peer. This issue can only happen if one or both of the BGP peers of the receiving session are non-4-byte-AS capable as determined from the advertised capabilities during BGP session establishment. Junos OS and Junos OS Evolved default behavior is 4-byte-AS capable unless this has been specifically disabled by configuring:

[ protocols bgp ... disable-4byte-as ]

Established BGP sessions can be checked by executing:

show bgp neighbor <IP address> | match "4 byte AS"

This issue affects:

Junos OS:

all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S5, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S2, 24.4 versions before 24.4R2;

Junos OS Evolved:

all versions before 22.4R3-S8-EVO, 23.2 versions before 23.2R2-S5-EVO, 23.4 versions before 23.4R2-S6-EVO, 24.2 versions before 24.2R2-S2-EVO, 24.4 versions before 24.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases; Junos OS: 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S2, 24.4R2, 25.2R1, and all subsequent releases.
First published (updated )
Severity
7.4
AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a DHCP client in one subnet to exhaust the address pools of other subnets, leading to a Denial of Service (DoS) on the downstream DHCP server.

By default, the DHCP relay agent inserts its own Option 82 information when forwarding client requests, optionally replacing any Option 82 information provided by the client. When a specific DHCP DISCOVER is received in 'forward-only' mode with Option 82, the device should drop the message unless 'trust-option82' is configured. Instead, the DHCP relay forwards these packets to the DHCP server unmodified, which uses up addresses in the DHCP server's address pool, ultimately leading to address pool exhaustion.

This issue affects Junos OS:

all versions before 21.2R3-S10, from 21.4 before 21.4R3-S12, all versions of 22.2, from 22.4 before 22.4R3-S8,  from 23.2 before 23.2R2-S5,  from 23.4 before 23.4R2-S6,  from 24.2 before 24.2R2-S2,  from 24.4 before 24.4R2,  from 25.2 before 25.2R1-S1, 25.2R2.

Junos OS Evolved:

all versions before 21.4R3-S12-EVO,  all versions of 22.2-EVO, from 22.4 before 22.4R3-S8-EVO,  from 23.2 before 23.2R2-S5-EVO,  from 23.4 before 23.4R2-S6-EVO,  from 24.2 before 24.2R2-S2-EVO,  from 24.4 before 24.4R2-EVO,  from 25.2 before 25.2R1-S1-EVO, 25.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 21.2R3-S10, 21.4R3-S12, 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S2, 24.4R2, 25.2R1-S1, 25.2R2, 25.4R1, and all subsequent releases. Junos OS Evolved 21.4R3-S12-EVO, 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-S1-EVO, 25.2R2-EVO, 25.4R1-EVO, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS).

When an affected system receives a specific BGP EVPN update message over an established BGP session, this causes an rpd crash and restart.

A BGP EVPN configuration is not necessary to be vulnerable. If peers are not configured to send BGP EVPN updates to a vulnerable device, then this issue can't occur.

This issue affects iBGP and eBGP, over IPv4 and IPv6.

This issue affects: Junos OS: 23.4 versions from

23.4R2-S3 before 23.4R2-S5, 24.2 versions from

24.2R2

before 24.2R2-S1, 24.4 versions before 24.4R1-S3, 24.4R2;

Junos OS Evolved: 23.4-EVO versions from 23.4R2-S2-EVO before 23.4R2-S5-EVO, 24.2-EVO versions from 24.2R2-EVO before 24.2R2-S1-EVO, 24.4-EVO versions before 24.4R1-S3-EVO, 24.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 23.4R2-S5-EVO, 24.2R2-S1-EVO, 24.4R1-S3-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases; Junos OS: 23.4R2-S5, 24.2R2-S1, 24.4R1-S3, 24.4R2, 25.2R1, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Use of Uninitialized Resource vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX4700 devices allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).

When forwarding-options sampling is enabled, receipt of any traffic destined to the Routing Engine (RE) by the PFE line card leads to an FPC crash and restart, resulting in a Denial of Service (DoS).

Continued receipt and processing of any traffic leading to the RE by the PFE line card will create a sustained Denial of Service (DoS) condition to the PFE line card.

This issue affects Junos OS on SRX4700:

from 24.4 before 24.4R1-S3, 24.4R2

This issue affects IPv4 and IPv6.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 24.4R1-S3, 24.4R2, 25.2R1 and all subsequent releases.
First published (updated )
Severity
7
AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos OS on EX4600 Series and QFX5000 Series allows an unauthenticated attacker with physical access to the device to create a backdoor which allows complete control of the system.

When a device isn't configured with a root password, an attacker can modify a specific file. It's contents will be added to the Junos configuration of the device without being visible. This allows for the addition of any configuration unknown

to the actual operator, which includes users, IP addresses and other configuration which could allow unauthorized access to the device. This exploit is persistent across reboots and even zeroization.

The indicator of compromise is a modified /etc/config/<platform>-defaults[-flex].conf file. Review that file for unexpected configuration statements, or compare it to an unmodified version which can be extracted from the original Juniper software image file. For details on the extraction procedure please contact Juniper Technical Assistance Center (JTAC).

To restore the device to a trusted initial configuration the system needs to be reinstalled from physical media.

This issue affects Junos OS on EX4600 Series and QFX5000 Series:

All versions before 21.4R3, 22.2 versions before 22.2R3-S3.

Remedy

The following software releases have been updated to resolve this specific issue: 21.4R3, 22.2R3-S3, 22.3R1, and all subsequent releases.
First published (updated )
Severity
8.2
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

A Buffer Copy without Checking Size of Input vulnerability in the

Session Initialization Protocol (SIP) ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).

When memory utilization is high, and specific SIP packets are received, flowd/mspmand crashes. While the system recovers automatically, the disruption can significantly impact service stability. Continuous receipt of these specific SIP packets, while high utilization is present, will cause a sustained DoS condition. The utilization is outside the attackers control, so they would not be able to deterministically exploit this. This issue affects Junos OS on SRX Series and MX Series:

All versions before 22.4R3-S7, from 23.2 before 23.2R2-S4, from 23.4 before 23.4R2-S5, from 24.2 before 24.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: 22.4R3-S7, 23.2R2-S4, 23.4R2-S5, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
8.4
OS Command Injection, Command Injection
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a high privileged, local attacker to escalated their privileges to root.

When a user provides specifically crafted arguments to the 'request system logout' command, these will be executed as root on the shell, which can completely compromise the device. This issue affects:

Junos OS:

all versions before 21.2R3-S9, 21.4 versions before 21.4R3-S8, 22.2 versions before 22.2R3-S6, 22.3 versions before 22.3R3-S3, 22.4 versions before 22.4R3-S6, 23.2 versions before 23.2R2-S1, 23.4 versions before 23.4R1-S2, 23.4R2;

Junos OS Evolved:

all versions before 22.4R3-S6-EVO, 23.2-EVO versions before 23.2R2-S1-EVO, 23.4-EVO versions before 23.4R1-S2-EVO, 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S6-EVO, 23.2R2-S1-EVO, 23.4R1-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases; Junos OS: 21.2R3-S9, 21.4R3-S8, 22.2R3-S6, 22.3R3-S3, 22.4R3-S6, 23.2R2-S1, 23.4R1-S2, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )
Severity
8.2
Null Pointer Dereference
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause impact to the availability of the device.

When static route points to a reject next hop and a gNMI query is processed for that static route, rpd crashes and restarts.

This issue affects:

Junos OS:  all versions before 21.2R3-S9, 21.4 versions before 21.4R3-S10,  22.2 versions before 22.2R3-S6, 22.4 versions before 22.4R3-S6, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R1-S2, 24.2R2;

Junos OS Evolved:

all versions before 22.4R3-S7-EVO, 23.2-EVO

versions before 23.2R2-S3-EVO, 23.4-EVO versions before 23.4R2-S4-EVO, 24.2-EVO versions before 24.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S7-EVO, 23.2R2-S3-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-EVO, and all subsequent releases; Junos OS: 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 23.4R2-S4, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
8.6
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A UI Discrepancy for Security Feature

vulnerability in the UI of Juniper Networks Junos OS on VM Host systems allows a network-based, unauthenticated attacker to access the device.

On VM Host Routing Engines (RE), even if the configured public key for root has been removed, remote users which are in possession of the corresponding private key can still log in as root. This issue affects Junos OS:

all versions before 22.2R3-S7, 22.4 versions before 22.4R3-S5, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S3, 24.2 versions before 24.2R1-S2, 24.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: 22.2R3-S7, 22.4R3-S5, 23.2R2-S3, 23.4R2-S3, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203