Impact
An unchecked input for loop condition in the Packet Forwarding Engine of Juniper Junos OS on MX Series allows an adjacent attacker to trigger a denial‑of‑service attack by causing the PFEMAN to process an unbounded queue of micro‑BFD events. The flaw arises when micro‑BFD sessions flap at a high rate; each up/down event is queued, and with locality‑bias enabled the processing time per event is significant. As new events keep arriving, PFEMAN is unable to finish, its watchdog timer expires, and the FPC crashes. The crash forces a FPC restart, resulting in a complete service outage for the affected router. CWE‑606, unchecked input for loop condition, describes the weakness underlying this fault.
Affected Systems
Juniper Networks Junos OS on MX Series routers. Affected hardware includes all MX Series Field Processing Engines (FPCs) up through MPC9 as well as the LC2101, LC2103 and LC480 chips. The flaw does not impact MPC10 or MPC11, LC4800 or LC4800/9600 series boards, and MX304. Software versions before 23.2R2‑S7, before 23.4R2‑S8, before 24.2R2‑S4, before 24.4R2‑S3 and before 25.2R2 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 places this issue in the high‑severity range, while the EPSS of <1 % indicates that exploitation probability remains very low at present. The vulnerability is not listed in CISA’s KEV catalog. network segment as the target and can exploit the flaw by generating a high rate of micro‑BFD session flaps; no authentication is required. The attack path is purely through the BFD control plane, and the flaw manifests as a denial‑of‑service via an FPC crash, affecting overall system availability.
OpenCVE Enrichment