Impact
An improper restriction of the communication channel exists in Juniper Networks Junos OS Evolved. A port that is meant to be used only internally is inadvertently left open, allowing an unauthenticated, network‑based attacker to reach a process that should not be exposed. This flaw enables limited information disclosure and causes excess CPU usage by processing inbound packets destined for the exposed port, which can degrade device availability. The vulnerability is classified as CWE‑923 and is identified as a moderate‑severity flaw with a CVSS score of 6.9.
Affected Systems
All Juniper Networks Junos OS Evolved devices running software prior to the following releases are affected: 23.2R2‑S7‑EVO, 23.4R2‑S8‑EVO, 24.2R2‑S5‑EVO, 24.4R2‑S4‑EVO, 25.2R2‑S1‑EVO, 25.4R1‑S2‑EVO.
Risk and Exploitability
The CVSS score indicates a moderate risk. EPSS score of < 1% suggests a very low exploitation probability, implying that while the vulnerability exists, the likelihood of being exploited in the wild is minimal. The flaw is not listed in CISA's KEV catalog. Because it allows unauthenticated access to a network‑outbound control‑plane port, an attacker could increase CPU load and potentially disrupt service. The primary attack vector is network‑based and requires no authentication, making it readily exploitable against exposed control‑plane ports.
OpenCVE Enrichment