Impact
An input validation causes the system to incorrectly calculate packet sizes for certain traffic types. When a specific packet is received from another device in the same broadcast domain—such as MAP‑T traffic or non‑IP traffic encapsulated in IP (e.g., MPLS over GRE)—the calculation overflow. The reset interrupts all traffic until the hardware automatically recovers, effectively creating a denial‑of‑service that is limited to the affected interfaces. This weakness is classified as CWE‑1284.
Affected Systems
Juniper Networks Junos OS running on MX Series devices with software versions earlier than 23.2R2‑S6, 23.4R2‑S7, 24.2R2‑S4, 24.4R2‑S4, and 25.2R2, as well as any releases before those update milestones; the issue is specifically triggered by MAP‑T traffic or non‑IP traffic encapsulated within IP such as MPLS over GRE in the same broadcast domain.
Risk and Exploitability
The vulnerability scores 7.1 on the CVSS scale and has an EPSS score of less than 1%, indicating a low but non‑zero exploitation probability. It is not listed in CISA’s KEV catalog. The flaw requires an unauthenticated attacker adjacent to the device on the same broadcast domain, who can craft packets that trigger the faulty size calculation, causing an FPC reset and an immediate denial‑of‑service that automatically resolves after the hardware recovers.
OpenCVE Enrichment