Impact
An authenticated user without any specific permissions can execute a privileged CLI 'request' command on Juniper Networks Junos OS for EX Series switches, causing a complete traffic impact until the system automatically recovers. The flaw is a Missing Authorization weakness (CWE‑862) that allows local attackers to trigger a service‑impacting denial‑of‑service condition. The impact is limited to the local device and results in downtime of network traffic handled by the switch.
Affected Systems
The vulnerability affects Juniper Networks Junos OS on EX 2300, EX 4000, EX 4100, EX 4300‑MP (Multigigabit), and EX 4400 switches. Affected releases include all versions of 23.2R2 before 23.2R2‑S6, 23.4 before 23.4R2‑S8, 24.2 before 24.2R2‑S4, 24.4 before 24.4R2‑S3, 25.2 before 25.2R2, and 25.4 before 25.4R1‑S1.
Risk and Exploitability
The CVSS base score is 6.8, categorizing it as a moderate severity issue; the EPSS score indicates a low exploitation probability (<1%). The vulnerability is not listed in the CISA KEV catalog. The vulnerability is exploitable from a local, authenticated context, meaning an attacker must already have user credentials or physical access to the device. Once the command is run, the switch experiences a denial‑of-service that persists until the system reboots or recovers automatically. A workaround is to apply command authorization to limit the 'request' command to privileged users only, but the primary mitigation remains applying any of the patched releases.
OpenCVE Enrichment