Where
AND
-Infinity
0
Severity
8.4
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root.

This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include: MPC7, MPC8, MPC9, MPC10, MPC11 LC2101, LC2103 LC480, LC4800, LC9600 MX304 (built-in FPC) MX-SPC3 SRX5K-SPC3 EX9200-40XS

FPC3-PTX-U2, FPC3-PTX-U3 FPC3-SFF-PTX LC1101, LC1102, LC1104, LC1105

This issue affects Junos OS:

all versions before 22.4R3-S8,  from 23.2 before 23.2R2-S6,  from 23.4 before 23.4R2-S6,  from 24.2 before 24.2R2-S3,  from 24.4 before 24.4R2, from 25.2 before 25.2R2.

First published (updated )
Severity
7.1
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS).

Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd crash occurs before the update can be readvertised, so there is no downstream propagation.

This issue affects:

Junos OS versions 25.2 before 25.2R2;

Junos OS Evolved versions 25.2 before 25.2R2-EVO.

This issue doesn't affect Junos OS versions before 25.2R1 nor Junos OS Evolved versions before 25.2R1-EVO.

First published (updated )
Severity
7.5
EPSS
0.09%
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access sensitive system information.

When a user logs in, a temporary file which contains the configuration of the device (as visible to that user) is created in the /cache folder. An unauthenticated attacker can then attempt to access such a file by sending a specific request to the device trying to guess the name of such a file. Successful exploitation will reveal configuration information.

This issue affects Juniper Networks Junos OS on SRX Series and EX Series: All versions earlier than 20.4R3-S9; 21.2 versions earlier than 21.2R3-S7; 21.3 versions earlier than 21.3R3-S5; 21.4 versions earlier than 21.4R3-S6; 22.1 versions earlier than 22.1R3-S5; 22.2 versions earlier than 22.2R3-S3; 22.3 versions earlier than 22.3R3-S2; 22.4 versions earlier than 22.4R3; 23.2 versions earlier than 23.2R1-S2, 23.2R2.

First published (updated )
Severity
8.8
EPSS
0.05%
XSS
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator.

A specific invocation of the emitdebugnote method in webauthoperation.php will echo back the data it receives.

This issue affects Juniper Networks Junos OS on SRX Series and EX Series: All versions earlier than 20.4R3-S10; 21.2 versions earlier than 21.2R3-S8; 21.4 versions earlier than 21.4R3-S6; 22.1 versions earlier than 22.1R3-S5; 22.2 versions earlier than 22.2R3-S3; 22.3 versions earlier than 22.3R3-S2; 22.4 versions earlier than 22.4R3-S1; 23.2 versions earlier than 23.2R2; 23.4 versions earlier than 23.4R2.

First published (updated )
Severity
7.1
Input Validation
AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS).

An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS:

25.2 versions before 25.2R2

This issue does not affect Junos OS versions before 25.2R1.

This issue affects Junos OS Evolved: 25.2-EVO versions before 25.2R2-EVO

This issue does not affect Junos OS Evolved versions before 25.2R1-EVO.

eBGP and iBGP are affected. IPv4 and IPv6 are affected.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 25.2R2, 25.4R1, and all subsequent releases. Junos OS Evolved: 25.2R2-EVO, 25.4R1-EVO, and all subsequent releases.
First published (updated )
Severity
8.4
OS Command Injection, Command Injection
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete compromise of the system.

Certain 'set system' commands, when executed with crafted arguments, are not properly sanitized, allowing for arbitrary shell injection. These shell commands are executed as root, potentially allowing for complete control of the vulnerable system. This issue affects:

Junos OS:

all versions before 22.4R3-S8,  from 23.2 before 23.2R2-S5,  from 23.4 before 23.4R2-S7,  from 24.2 before 24.2R2-S2,  from 24.4 before 24.4R2,  from 25.2 before 25.2R2;

Junos OS Evolved:

all versions before 22.4R3-S8-EVO,  from 23.2 before 23.2R2-S5-EVO,  from 23.4 before 23.4R2-S7-EVO,  from 24.2 before 24.2R2-S2-EVO,  from 24.4 before 24.4R2-EVO,  from 25.2 before 25.2R1-S1-EVO, 25.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 22.4R3-S8, 23.2R2-S5, 23.4R2-S7, 24.2R2-S2, 24.4R2, 25.2R2, 25.4R1, and all subsequent releases. Junos OS Evolved 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-S7-EVO, 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-S1-EVO, 25.2R2-EVO, 25.4R1-EVO, and all subsequent releases.
First published (updated )
Severity
7
AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root which will lead to a complete compromise of the system.

When after a user has performed a specific 'file link ...' CLI operation, another user commits (unrelated configuration changes), the first user can login as root.

This issue affects Junos OS: all versions before 23.2R2-S7, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S3, 24.4 versions before 24.4R2-S2, 25.2 versions before 25.2R2.

This issue does not affect versions 25.4R1 or later.

Remedy

The following software releases have been updated to resolve this specific issue: 23.2R2-S7, 23.4R2-S6, 24.2R2-S3, 24.4R2-S2, 25.2R2, and all subsequent releases.
First published (updated )
Severity
7.1
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to cause a complete Denial-of-Service (DoS) of the management plane.

When NETCONF sessions are quickly established and disconnected, a locking issue causes mgd processes to hang in an unusable state. When the maximum number of mgd processes has been reached, no new logins are possible. This leads to the inability to manage the device and requires a power-cycle to recover.

This issue can be monitored by checking for mgd processes in lockf state in the output of 'show system processes extensive':

user@host> show system processes extensive | match mgd <pid> root       20   0 501M 4640K lockf   1 0:01 0.00% mgd

If the system still can be accessed (either via the CLI or as root, which might still be possible as last resort as this won't invoke mgd), mgd processes in this state can be killed with 'request system process terminate <PID>' from the CLI or with 'kill -9 <PID>' from the shell.

This issue affects:

Junos OS:

23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2-S1, 24.4 versions before 24.4R1-S3, 24.4R2;

This issue does not affect Junos OS versions before 23.4R1;

Junos OS Evolved:

23.4 versions before 23.4R2-S5-EVO, 24.2 versions before 24.2R2-S1-EVO, 24.4 versions before 24.4R1-S3-EVO, 24.4R2-EVO.

This issue does not affect Junos OS Evolved versions before 23.4R1-EVO;

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 23.4R2-S5-EVO, 24.2R2-S1-EVO, 24.4R1-S3-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases; Junos OS: 23.4R2-S4, 24.2R2-S1, 24.4R1-S3, 24.4R2, 25.2R1, and all subsequent releases.
First published (updated )
Severity
7.1
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultimately leading to a Denial of Service (DoS).

In an EVPN-MPLS scenario, routes learned from remote multi-homed Provider Edge (PE) devices are programmed as ESI routes. Due to a logic issue in the l2ald memory management, memory allocated for these routes is not released when there is churn for these routes. As a result, memory leaks in the l2ald process which will ultimately lead to a crash and restart of l2ald.

Use the following command to monitor the memory consumption by l2ald:

user@device> show system process extensive | match "PID|l2ald"

This issue affects:

Junos OS:

all versions before 22.4R3-S5, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2;

Junos OS Evolved:

all versions before 22.4R3-S5-EVO, 23.2 versions before 23.2R2-S3-EVO, 23.4 versions before 23.4R2-S4-EVO, 24.2 versions before 24.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S5-EVO, 23.2R2-S3-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-EVO, and all subsequent releases; Junos OS: 22.4R3-S5, 23.2R2-S3, 23.4R2-S4, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
8.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system.

When a configuration that allows unsigned Python op scripts is present on the device, a non-root user is able to execute malicious op scripts as a root-equivalent user, leading to privilege escalation.

This issue affects Junos OS:

All versions before 22.4R3-S7,  from 23.2 before 23.2R2-S4,  from 23.4 before 23.4R2-S6, from 24.2 before 24.2R1-S2, 24.2R2,  from 24.4 before 24.4R1-S2, 24.4R2;

Junos OS Evolved:

All versions before 22.4R3-S7-EVO,  from 23.2 before 23.2R2-S4-EVO,  from 23.4 before 23.4R2-S6-EVO, from 24.2 before 24.2R2-EVO,  from 24.4 before 24.4R1-S1-EVO, 24.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S7-EVO, 23.2R2-S4-EVO, 23.4R2-S6-EVO, 24.2R2-EVO, 24.4R1-S1-EVO, 24.4R2-EVO, 25.2R1-EVO and all subsequent releases. Junos OS: 22.4R3-S7, 23.2R2-S4, 23.4R2-S6, 24.2R1-S2, 24.2R2, 24.4R1-S2, 24.4R2, 25.2R1 and all subsequent releases.
First published (updated )
Severity
7.1
EPSS
0.02%
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an unauthenticated, network-adjacent attacker sending a specifically malformed ICMP packet to cause an FPC to crash and restart, resulting in a Denial of Service (DoS).

When an ICMP packet is received with a specifically malformed IP header value, the FPC receiving the packet crashes and restarts. Due to the specific type of malformed packet, adjacent upstream routers would not forward the packet, limiting the attack surface to adjacent networks.

This issue only affects ICMPv4. ICMPv6 is not vulnerable to this issue.

This issue does not affect AFT-based line cards such as the MPC10, MPC11, LC4800, LC9600, and MX304.

This issue affects Junos OS:

all versions before 21.2R3-S9,  from 21.4 before 21.4R3-S10,  from 22.2 before 22.2R3-S7,  from 22.3 before 22.3R3-S4,  from 22.4 before 22.4R3-S5,  from 23.2 before 23.2R2-S3,  from 23.4 before 23.4R2-S3,  from 24.2 before 24.2R1-S2, 24.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 20.2R3-S10, 21.2R3-S9, 21.4R3-S10, 22.2R3-S7, 22.3R3-S4, 22.4R3-S5, 23.2R2-S3, 23.4R2-S3, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
7.7
Buffer Overflow
AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

A Heap-based Buffer Overflow vulnerability in the flexible PIC concentrator (FPC) of Juniper Networks Junos OS on EX2300, EX3400, EX4100, EX4300, EX4300MP, EX4400, EX4600, EX4650-48Y, and QFX5k Series allows an attacker to send a specific DHCP packet to the device, leading to an FPC crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.

Under a rare timing scenario outside the attacker's control, memory corruption may be observed when DHCP Option 82 is enabled, leading to an FPC crash and affecting packet forwarding. Due to the nature of the heap-based overflow, exploitation of this vulnerability could also lead to remote code execution within the FPC, resulting in complete control of the vulnerable component. This issue affects Junos OS on EX2300, EX3400, EX4100, EX4300, EX4300MP, EX4400, EX4600, EX4650-48Y, and QFX5k Series:

All versions before 21.4R3-S9,  from 22.2 before 22.2R3-S5,  from 22.4 before 22.4R3-S5,  from 23.2 before 23.2R2-S3,  from 23.4 before 23.4R2-S3,  from 24.2 before 24.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: 21.4R3-S9, 22.2R3-S5, 22.4R3-S5, 23.2R2-S3, 23.4R2-S3, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
8.5
AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Networks Junos OS allows a local, low-privileged user to install scripts to be executed as root, leading to privilege escalation.

A local user with access to the local file system can copy a script to the router in a way that will be executed as root, as the system boots. Execution of the script as root can lead to privilege escalation, potentially providing the adversary complete control of the system.

This issue only affects specific line cards, such as the MPC10, MPC11, LC4800, LC9600, MX304-LMIC16, SRX4700, and EX9200-15C.

This issue affects Junos OS: from 23.2 before 23.2R2-S4,  from 23.4 before 23.4R2-S5,  from 24.2 before 24.2R2-S1,  from 24.4 before 24.4R1-S3, 24.4R2.

This issue does not affect versions prior to 23.1R2.

Remedy

The following software releases have been updated to resolve this specific issue: 23.4R2-S4, 24.2R2-S1, 24.4R1-S3, 24.4R2, 25.2R1, and all subsequent releases.
First published (updated )
Severity
8.4
OS Command Injection, Command Injection
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a high privileged, local attacker to escalated their privileges to root.

When a user provides specifically crafted arguments to the 'request system logout' command, these will be executed as root on the shell, which can completely compromise the device. This issue affects:

Junos OS:

all versions before 21.2R3-S9, 21.4 versions before 21.4R3-S8, 22.2 versions before 22.2R3-S6, 22.3 versions before 22.3R3-S3, 22.4 versions before 22.4R3-S6, 23.2 versions before 23.2R2-S1, 23.4 versions before 23.4R1-S2, 23.4R2;

Junos OS Evolved:

all versions before 22.4R3-S6-EVO, 23.2-EVO versions before 23.2R2-S1-EVO, 23.4-EVO versions before 23.4R1-S2-EVO, 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S6-EVO, 23.2R2-S1-EVO, 23.4R1-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases; Junos OS: 21.2R3-S9, 21.4R3-S8, 22.2R3-S6, 22.3R3-S3, 22.4R3-S6, 23.2R2-S1, 23.4R1-S2, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )
Severity
8.6
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A UI Discrepancy for Security Feature

vulnerability in the UI of Juniper Networks Junos OS on VM Host systems allows a network-based, unauthenticated attacker to access the device.

On VM Host Routing Engines (RE), even if the configured public key for root has been removed, remote users which are in possession of the corresponding private key can still log in as root. This issue affects Junos OS:

all versions before 22.2R3-S7, 22.4 versions before 22.4R3-S5, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S3, 24.2 versions before 24.2R1-S2, 24.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: 22.2R3-S7, 22.4R3-S5, 23.2R2-S3, 23.4R2-S3, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
7.5
EPSS
0.04%
Use After Free
AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

A Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Juniper Networks Junos OS and Junos OS Evolved that could allow an authenticated, network-adjacent attacker flapping a port to crash the dot1xd process, leading to a Denial of Service (DoS), or potentially execute arbitrary code within the context of the process running as root.

The issue is specific to the processing of a change in authorization (CoA) when a port bounce occurs. A pointer is freed but was then referenced later in the same code path. Successful exploitation is outside the attacker's direct control due to the specific timing of the two events required to execute the vulnerable code path.

This issue affects systems with 802.1X authentication port-based network access control (PNAC) enabled. This issue affects:

Junos OS:

from 23.2R2-S1 before 23.2R2-S5,  from 23.4R2 before 23.4R2-S6,  from 24.2 before 24.2R2-S3,  from 24.4 before 24.4R2-S1,  from 25.2 before 25.2R1-S2, 25.2R2;

Junos OS Evolved:

from 23.2R2-S1 before 23.2R2-S5-EVO,  from 23.4R2 before 23.4R2-S6-EVO,  from 24.2 before 24.2R2-S3-EVO,  from 24.4 before 24.4R2-S1-EVO,  from 25.2 before 25.2R1-S2-EVO, 25.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 23.2R2-S5, 23.4R2-S6, 24.2R2-S3, 24.4R2-S1, 25.2R1-S2, 25.2R2, 25.4R1, and all subsequent releases. Junos OS Evolved: 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S3-EVO, 24.4R2-S1-EVO, 25.2R1-S2-EVO, 25.2R2-EVO, 25.4R1-EVO,
First published (updated )
Severity
7.1
EPSS
0.02%
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on EX4k Series and QFX5k Series platforms allows an unauthenticated network-adjacent attacker flapping an interface to cause traffic between VXLAN Network Identifiers (VNIs) to drop, leading to a Denial of Service (DoS).

On all EX4k and QFX5k platforms, a link flap in an

EVPN-VXLAN configuration Link Aggregation Group (LAG) results in Inter-VNI traffic dropping when there are multiple load-balanced next-hop routes for the same destination.

This issue is only applicable to systems that support EVPN-VXLAN Virtual Port-Link Aggregation Groups (VPLAG), such as the QFX5110, QFX5120, QFX5200, EX4100, EX4300, EX4400, and EX4650.

Service can only be restored by restarting the affected FPC via the 'request chassis fpc restart slot <slot-number>' command.

This issue affects Junos OS

on EX4k and QFX5k Series:

all versions before 21.4R3-S12,  all versions of 22.2 from 22.4 before 22.4R3-S8,  from 23.2 before 23.2R2-S5,  from 23.4 before 23.4R2-S5,  from 24.2 before 24.2R2-S3, from 24.4 before 24.4R2.

First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on

SRX1600, SRX2300, SRX 4000 Series, and SRX5000 Series with SPC3

allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

If a sequence of specific PIM packets is received, this will cause a flowd crash and restart.

This issue affects Junos OS:

all versions before 21.2R3-S9, 21.4 versions before 21.4R3-S11, 22.2 versions before 22.2R3-S7, 22.4 versions before 22.4R3-S6, 23.2 versions before 23.2R2-S4, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2.

This is a similar, but different vulnerability than the issue reported as

CVE-2024-47503, published in JSA88133.

First published (updated )
Severity
7.4
AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

A Buffer Access with Incorrect Length Value vulnerability in the jdhcpd daemon of Juniper Networks Junos OS, when DHCP snooping is enabled, allows an unauthenticated, adjacent, attacker to send a DHCP packet with a malformed DHCP option to cause jdhcp to crash creating a Denial of Service (DoS) condition.

Continuous receipt of these DHCP packets using the malformed DHCP Option will create a sustained Denial of Service (DoS) condition.

This issue affects Junos OS:

from 23.1 before 23.2R2-S3, from 23.4 before 23.4R2-S3, from 24.2 before 24.2R2.

This issue isn't applicable to any versions of Junos OS before 23.1R1.

This issue doesn't affect vSRX Series which doesn't support DHCP Snooping.

This issue doesn't affect Junos OS Evolved.

There are no indicators of compromise for this issue.

Remedy

The following software releases have been updated to resolve this specific issue: 23.2R2-S3, 23.4R2-S3, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
7.1
EPSS
0.04%
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS).

On devices with SRv6 (Segment Routing over IPv6) enabled, an attacker can send a malformed BGP UPDATE packet which will cause the rpd to crash and restart. Continued receipt of these UPDATE packets will cause a sustained DoS condition.

This issue affects iBGP and eBGP, and both IPv4 and IPv6 are affected by this vulnerability.This issue affects Junos OS:

All versions before 21.2R3-S9,  from 21.4 before 21.4R3-S10,  from 22.2 before 22.2R3-S5,  from 22.3 before 22.3R3-S4,  from 22.4 before 22.4R3-S3,  from 23.2 before 23.2R2-S2,  from 23.4 before 23.4R2;

and Junos OS Evolved:

All versions before 21.2R3-S9-EVO,  from 21.4-EVO before 21.4R3-S10-EVO,  from 22.2-EVO before 22.2R3-S5-EVO,  from 22.3-EVO before 22.3R3-S4-EVO,  from 22.4-EVO before 22.4R3-S3-EVO, from 23.2-EVO before 23.2R2-S2-EVO,  from 23.4-EVO before 23.4R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 21.2R3-S9, 21.4R3-S10, 22.2R3-S5, 22.3R3-S4, 22.4R3-S3, 23.2R2-S2, 23.4R2, 24.2R1, and all subsequent releases. Junos OS Evolved: 21.2R3-S9-EVO, 21.4R3-S10-EVO, 22.2R3-S5-EVO, 22.3R3-S4-EVO, 22.4R3-S3-EVO, 23.2R2-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases.
First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Check for Unusual or Exceptional Conditions vulnerability in the pfe (packet forwarding engine) of Juniper Networks Junos OS on MX Series causes a port within a pool to be blocked leading to Denial of Service (DoS).

In a DS-Lite (Dual-Stack Lite) and NAT (Network Address Translation) scenario, when crafted IPv6 traffic is received and prefix-length is set to 56, the ports assigned to the user will not be freed.  Eventually, users cannot establish new connections. Affected FPC/PIC need to be manually restarted to recover. Following is the command to identify the issue:

user@host> show services nat source port-block      HostIP                     ExternalIP                   PortBlock      PortsUsed/       BlockState/                                                               Range           PortsTotal       LeftTime(s)     2001::                        x.x.x.x                     58880-59391     256/2561         Active/-       >>>>>>>>port still usedThis issue affects Junos OS on MX Series:

from 21.2 before 21.2R3-S8,  from 21.4 before 21.4R3-S7,  from 22.1 before 22.1R3-S6,  from 22.2 before 22.2R3-S4,  from 22.3 before 22.3R3-S3,  from 22.4 before 22.4R3-S2,  from 23.2 before 23.2R2-S1,  from 23.4 before 23.4R1-S2, 23.4R2.

This issue does not affect versions before 20.2R1.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 21.2R3-S8, 21.4R3-S7, 22.1R3-S6, 22.2R3-S4, 22.3R3-S3, 22.4R3-S2, 23.2R2-S1, 23.4R1-S2, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )
Severity
7.1
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause an FPC to crash, leading to Denial of Service (DoS).

On all Junos OS and Junos OS Evolved platforms, in an EVPN-VXLAN scenario, when specific ARP packets are received on an IPv4 network, or specific NDP packets are received on an IPv6 network, kernel heap memory leaks, which eventually leads to an FPC crash and restart.

This issue does not affect MX Series platforms. Heap size growth on FPC can be seen using below command.

user@host> show chassis fpc                     Temp CPU Utilization (%) CPU Utilization (%) Memory   Utilization (%) Slot State           (C) Total Interrupt     1min   5min   15min   DRAM (MB)   Heap   Buffer   0 Online           45     3         0       2       2      2       32768      19       0 <<<<<<< Heap increase in all fPCs

This issue affects Junos OS:

All versions before 21.2R3-S7, 21.4 versions before 21.4R3-S4, 22.2 versions before 22.2R3-S1,  22.3 versions before 22.3R3-S1,  22.4 versions before 22.4R2-S2, 22.4R3.

and Junos OS Evolved:

All versions before 21.2R3-S7-EVO, 21.4-EVO versions before 21.4R3-S4-EVO, 22.2-EVO versions before 22.2R3-S1-EVO,  22.3-EVO versions before 22.3R3-S1-EVO,

22.4-EVO versions before 22.4R3-EVO.

Remedy

The following software releases have been updated to resolve this specific issue. Junos OS: 21.2R3-S7, 21.4R3-S4, 22.2R3-S1, 22.3R3-S1, 22.4R2-S2, 22.4R3, 23.2R1, and all subsequent releases. Junos OS Evolved: 21.2R3-S7-EVO, 21.4R3-S4-EVO, 22.2R3-S1-EVO, 22.3R3-S1-EVO, 22.4R3-EVO, 23.2R1-EVO, and all subsequent releases.
First published (updated )
Severity
8.2
EPSS
0.05%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options enabled to crash rpd. This issue affects:

Junos OS:

from 21.2R3-S8 before 21.2R3-S9,  from 21.4R3-S7 before 21.4R3-S9,  from 22.2R3-S4 before 22.2R3-S5,  from 22.3R3-S2 before 22.3R3-S4,  from 22.4R3 before 22.4R3-S5,  from 23.2R2 before 23.2R2-S2,  from 23.4R1 before 23.4R2-S1,  from 24.2R1 before 24.2R1-S1, 24.2R2.

Junos OS Evolved: from 21.4R3-S7-EVO before 21.4R3-S9-EVO,  from 22.2R3-S4-EVO before 22.2R3-S5-EVO,  from 22.3R3-S2-EVO before 22.3R3-S4-EVO,  from 22.4R3-EVO before 22.4R3-S5-EVO,  from 23.2R2-EVO before 23.2R2-S2-EVO,  from 23.4R1-EVO before 23.4R2-S1-EVO,  from 24.2R1-EVO before 24.2R1-S2-EVO, 24.2R2-EVO.

This issue requires a BGP session to be established.

This issue can propagate and multiply through multiple ASes until reaching vulnerable devices.

This issue affects iBGP and eBGP.

This issue affects IPv4 and IPv6.

An indicator of compromise may be the presence of malformed update messages in a neighboring AS which is unaffected by this issue:

For example, by issuing the command on the neighboring device:  show log messages

Reviewing for similar messages from devices within proximity to each other may indicate this malformed packet is propagating:   rpd[<pid>]: Received malformed update from <IP address> (External AS <AS#>) and   rpd[<pid>]: Malformed Attribute

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 21.2R3-S9, 21.4R3-S9, 22.2R3-S5, 22.3R3-S4, 22.4R3-S5, 23.2R2-S2, 23.4R2-S1, 24.2R1-S1, 24.2R2, 24.4R1, and all subsequent releases. Junos OS Evolved: 21.4R3-S9-EVO, 22.2R3-S5-EVO, 22.3R3-S4-EVO, 22.4R3-S5-EVO, 23.2R2-S2-EVO, 23.4R2-S1-EVO, 24.2R1-S2-EVO, 24.2R2-EVO, 24.4R1-EVO, and all subsequent releases.
First published (updated )
Severity
7.1
EPSS
0.04%
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Out-of-Bounds Read vulnerability in

the routing protocol daemon (rpd) of

Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.

This issue only affects systems configured in either of two ways:

systems with BGP traceoptions enabled

systems with BGP family traffic-engineering (BGP-LS) configured

and can be exploited from a directly connected and configured BGP peer.

This issue affects iBGP and eBGP

with

any address family

configured, and both IPv4 and IPv6 are affected by this vulnerability.

This issue affects:

Junos OS:

from 21.4 before 21.4R3-S9,  from 22.2 before 22.2R3-S5,  from 22.3 before 22.3R3-S4,  from 22.4 before 22.4R3-S5,  from 23.2 before 23.2R2-S3,  from 23.4 before 23.4R2-S3,  from 24.2 before 24.2R1-S2, 24.2R2;

Junos OS Evolved:

from 21.4-EVO before 21.4R3-S9-EVO,  from 22.2-EVO before 22.2R3-S5-EVO,  from 22.3-EVO before 22.3R3-S4-EVO,  from 22.4-EVO before 22.4R3-S5-EVO,  from 23.2-EVO before 23.2R2-S3-EVO,  from 23.4-EVO before 23.4R2-S2-EVO,  from 24.2-EVO before 24.2R1-S2-EVO, 24.2R2-EVO.

This issue does not affect versions of Junos OS prior to 21.3R1.

This issue does not affect versions of Junos OS Evolved prior to 21.3R1-EVO.

This is a similar, but different vulnerability than the issue reported as CVE-2024-39516.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 21.4R3-S9, 22.2R3-S5, 22.3R3-S4, 22.4R3-S5, 23.2R2-S3, 23.4R2-S3, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases. Junos OS Evolved: 21.4R3-S9-EVO, 22.2R3-S5-EVO, 22.3R3-S4-EVO, 22.4R3-S5-EVO, 23.2R2-S3-EVO, 23.4R2-S2-EVO, 24.2R1-S2-EVO, 24.2R2-EVO, 24.4R1-EVO, and all subsequent releases.
First published (updated )
Severity
7.1
EPSS
0.04%
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a specific BGP update packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS).

Continuous receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.

This issue affects iBGP and eBGP, and both IPv4 and IPv6 are affected by this vulnerability.

This issue affects Junos OS:

from 21.4 before 21.4R3-S9,  from 22.2 before 22.2R3-S5,  from 22.3 before 22.3R3-S4, from 22.4 before 22.4R3-S5,  from 23.2 before 23.2R2-S3,  from 23.4 before 23.4R2-S3,  from 24.2 before 24.2R1-S2, 24.2R2;

This issue does not affect versions prior to 21.1R1.

Junos OS Evolved:

from 21.4 before 21.4R3-S9-EVO,  from 22.2 before 22.2R3-S5-EVO,  from 22.3 before 22.3R3-S4-EVO, from 22.4 before 22.4R3-S5-EVO,  from 23.2 before 23.2R2-S3-EVO,  from 23.4 before 23.4R2-S3-EVO,  from 24.2 before 24.2R1-S2-EVO, 24.2R2-EVO.

This issue does not affect versions prior to 21.1R1-EVO

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 21.4R3-S9-EVO, 22.2R3-S5-EVO, 22.3R3-S4-EVO, 22.4R3-S5-EVO, 23.2R2-S3-EVO*, 23.4R2-S3-EVO, 24.2R1-S2-EVO, 24.2R2-EVO*, 24.4R1-EVO, and all subsequent releases. Junos OS: 21.4R3-S9, 22.2R3-S5, 22.3R3-S4, 22.4R3-S5, 23.2R2-S3*, 23.4R2-S3, 24.2R1-S2, 24.2R2*, 24.4R1, and all subsequent releases. * Future Release
First published (updated )
Severity
8.7
Null Pointer Dereference
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A NULL Pointer Dereference vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker causing specific, valid control traffic to be sent out of a Dual-Stack (DS) Lite tunnel to crash the flowd process, resulting in a Denial of Service (DoS).  Continuous triggering of specific control traffic will create a sustained Denial of Service (DoS) condition.

On all SRX platforms, when specific, valid control traffic needs to be sent out of a DS-Lite tunnel, a segmentation fault occurs within the flowd process, resulting in a network outage until the flowd process restarts.

This issue affects Junos OS on SRX Series: All versions before 21.2R3-S9, from 21.4 before 21.4R3-S9, from 22.2 before 22.2R3-S5, from 22.4 before 22.4R3-S6, from 23.2 before 23.2R2-S3, from 23.4 before 23.4R2.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS 21.2R3-S9, 21.4R3-S9, 22.2R3-S5, 22.4R3-S6, 23.2R2-S3, 23.4R2, 24.2R1, and all subsequent releases.
First published (updated )
Severity
7.1
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Signed to Unsigned Conversion Error vulnerability in the Layer 2 Control Protocol daemon (l2cpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated adjacent attacker sending a specifically malformed LLDP TLV to cause the l2cpd process to crash and restart, causing a Denial of Service (DoS).  Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.

When an LLDP telemetry subscription is active, receipt of a specifically malformed LLDP TLV causes the l2cpd process to crash and restart.

This issue affects:

Junos OS:

All versions before 21.2R3-S9,  from 21.4 before 21.4R3-S10,  from 22.2 before 22.2R3-S6,  from 22.4 before 22.4R3-S6,  from 23.2 before 23.2R2-S3,  from 23.4 before 23.4R2-S4,  from 24.2 before 24.2R2;

Junos OS Evolved:

All versions before 21.4R3-S10-EVO, from 22.2-EVO before 22.2R3-S6-EVO,  from 22.4-EVO before 22.4R3-S6-EVO,  from 23.2-EVO before 23.2R2-S3-EVO,  from 23.4-EVO before 23.4R2-S4-EVO,  from 24.2-EVO before 24.2R2-EVO.

Remedy

The following software releases have been updated to resolve this specific issue:  Junos OS: 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 23.4R2-S4, 24.2R2, 24.4R1, and all subsequent releases. Junos OS Evolved: 21.4R3-S10-EVO, 22.2R3-S6-EVO, 22.4R3-S6-EVO, 23.2R2-S3-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-EVO, and all subsequent releases.
First published (updated )
Severity
7.1
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS).

In a subscriber management scenario, login/logout activity triggers a memory leak, and the leaked memory gradually increments and eventually results in a crash.                 user@host> show chassis fpc                                        Temp    CPU Utilization (%)   CPU Utilization (%)   Memory     Utilization (%)                       Slot State       (C)     Total   Interrupt     1min   5min  15min    DRAM (MB)  Heap   Buffer

2 Online         36       10         0          9     8     9        32768      26         0

This issue affects Junos OS on MX Series: All versions before 21.2R3-S9 from 21.4 before 21.4R3-S10 from 22.2 before 22.2R3-S6 from 22.4 before 22.4R3-S5 from 23.2 before 23.2R2-S3 from 23.4 before 23.4R2-S3 from 24.2 before 24.2R2.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S5, 23.2R2-S3, 23.4R2-S3, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
7.4
Input Validation
AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

An Improper Input Validation vulnerability in the Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause the jdhcpd process to crash resulting in a Denial of Service (DoS).

When a specifically malformed DHCP packet is received from a DHCP client, the jdhcpd process crashes, which will lead to the unavailability of the DHCP service and thereby resulting in a sustained DoS. The DHCP process will restart automatically to recover the service.

This issue will occur when dhcp-security is enabled.  This issue affects Junos OS:

All versions before 21.2R3-S9,  from 21.4 before 21.4R3-S10,  from 22.2 before 22.2R3-S6,  from 22.4 before 22.4R3-S6,  from 23.2 before 23.2R2-S3,  from 23.4 before 23.4R2-S4,  from 24.2 before 24.2R2;

Junos OS Evolved:  from 22.4 before 22.4R3-S6-EVO,  from 23.2 before 23.2R2-S3-EVO,  from 23.4 before 23.4R2-S4-EVO,  from 24.2 before 24.2R2-EVO.

.

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S6-EVO, 23.2R2-S3-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R1-EVO, and all subsequent releases. Junos: 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 23.4R2-S4, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )
Severity
8.7
Input Validation
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An Improper Input Validation vulnerability in the syslog stream TCP transport of Juniper Networks Junos OS on MX240, MX480 and MX960 devices with MX-SPC3 Security Services Card allows an unauthenticated, network-based attacker, to send specific spoofed packets to cause a CPU Denial of Service (DoS) to the MX-SPC3 SPUs.

Continued receipt and processing of these specific packets will sustain the DoS condition.

This issue affects Junos OS: All versions before 22.2R3-S6, from 22.4 before 22.4R3-S4, from 23.2 before 23.2R2-S3, from 23.4 before 23.4R2-S4, from 24.2 before 24.2R1-S2, 24.2R2

An indicator of compromise will indicate the SPC3 SPUs utilization has spiked.

For example:     user@device> show services service-sets summary Service sets CPU Interface configured Bytes used Session bytes used Policy bytes used utilization "interface" 1 "bytes" (percent%) "sessions" ("percent"%) "bytes" ("percent"%) 99.97 % OVLD <<<<<< look for high CPU usage

Remedy

The following software releases have been updated to resolve this specific issue: Junos OS: 22.2R3-S6, 22.4R3-S4, 23.2R2-S3, 23.4R2-S4, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203