Impact
An out‑of‑bounds write vulnerability in Juniper Networks’ SNMP daemon (snmpd) allows an authenticated, network‑based attacker to trigger a memory leak by sending particular SNMPv3 queries. Repeated requests gradually exhaust snmpd’s memory, causing the process to crash and restart. The crash disables SNMP monitoring, resulting in a denial of service for management and performance‑monitoring functions.
Affected Systems
Juniper Networks Junos OS and Junos OS Evolved. All releases older than Junos OS 21.2R3‑S8, 21.4R3‑S7, 22.1R3‑S6, 22.2R3‑S4, 22.3R3‑S3, 22.4R3‑S2, 23.2R2 or 23.4R2 are vulnerable. In Junos OS Evolved, all releases before 21.2R3‑S8‑EVO, 21.4R3‑S7‑EVO, 22.2R3‑S4‑EVO, 22.3R3‑S3‑EVO, 23.2R2‑EVO, 23.4R2‑EVO as well as the entire 22.1‑EVO and 22.4‑EVO series are affected.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of <1% reflects a low likelihood of exploitation. The vulnerability requires network access to SNMPv3 with valid authentication and sustained traffic to exhaust memory, making it most realistic against an insider or an attacker who has compromised the management network. Because it is not listed in CISA’s KEV catalog, no known public exploits are cataloged, but the impact remains a denial of service for SNMP management. The path of attack involves sending legitimate SNMPv3 requests repeatedly, which the device treats as authenticated traffic and therefore processes, leading to the resource exhaustion that triggers the crash.
OpenCVE Enrichment