Impact
An out‑of‑bounds write in the http‑gatekeeper (http‑gk) component of Junos OS causes the http‑gk process to crash. The crash disrupts all services that rely on the system services web‑management configuration—such as J‑Web, remote‑access VPN, and firewall authentication—until the process automatically restarts. The weakness is classified as a memory corruption flaw (CWE‑787) and does not provide code execution or data disclosure.
Affected Systems
Juniper Networks Junos OS on SRX Series routers is affected. The vulnerable releases include any firmware versions before 23.2R2‑S7, 23.4R2‑S8, 24.2R2‑S4, 24.4R2‑S4, 25.2R2, 25.4R1‑S1, and 25.4R2. Devices running these firmware releases and configured for remote‑access VPN with pre‑logon compliance checking can be impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate impact. The EPSS score of < 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. A network‑based, unauthenticated attacker who can reach the device and send specially crafted requests to the‑gk process can trigger the crash. Although it causes a denial of service, it does not allow code execution or data exposure, so the risk is largely service disruption until mitigation is applied.
OpenCVE Enrichment