Impact
An out-of-bounds write in the http-gatekeeper (http-gk) component of Junos OS causes the http-gk process to crash. The crash disrupts all services that rely on the system services web-management configuration—such as J-Web, remote-access VPN, and firewall authentication—until the process automatically restarts. The weakness is classified as a memory corruption flaw (CWE-787) and does not provide code execution or data disclosure.
Affected Systems
Juniper Networks Junos OS on SRX Series routers is affected. The vulnerable releases include any firmware versions before 23.2R2-S7, 23.4R2-S8, 24.2R2-S4, 24.4R2-S4, 25.2R2, 25.4R1-S1, and 25.4R2. Devices running these firmware releases and configured for remote-access VPN with pre-logon compliance checking can be impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate impact. The EPSS score of < 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. A network-based, unauthenticated attacker who can reach the device and send specially crafted requests to the-gk process can trigger the crash. Although it causes a denial of service, it does not allow code execution or data exposure, so the risk is largely service disruption until mitigation is applied.
OpenCVE Enrichment