Impact
The vulnerability is an Improper Check for Unusual or Exceptional Conditions (CWE‑754) in the packet forwarding engine of Juniper Networks Junos OS on QFX10000 Series. When an unauthenticated adjacent attacker sends IPv6 multicast traffic to a non‑IRB interface in an EVPN‑VxLAN environment, the switch floods the packet to all other spine switches and leaf switches through the Ethernet Segment Identifier (ESI). The packet is forwarded in an endless loop, saturating interswitch links and disrupting legitimate traffic, resulting in a denial‑of‑service.
Affected Systems
The flaw affects Juniper Networks Junos OS on QFX10000 Series devices running any version prior to 23.2R2‑S7, to 23.4R2‑S8, to 24.2R2‑S4, or to 24.4R2‑S4. All firmware released after those dates and on unsupported hardware is considered safe, as the vulnerability is fixed in the patched releases 23.2R2‑S7, 23.4R2‑S8, 24.2R2‑S4, and 24.4R2‑S4.
Risk and Exploitability
The CVSS base score of 7.1 and an EPSS score of less than 1 % indicate a medium‑to‑high severity but a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs to be adjacent to the spine switch; no authentication is required, and the attack can be carried out by injecting multicast traffic into the local network. Successful exploitation would lead to link saturation and a widespread denial of service across the spine and leaf fabric.
OpenCVE Enrichment