Impact
An improper check for unusual or exceptional conditions in Juniper’s Packet Forwarding Engine (PFE) can cause it to crash when a device, after initiating a TCP connection to a remote host, receives a specially crafted response packet. The crash forces the PFE to restart, temporarily disabling all services on the device until the hardware recovers. Because the flaw can be triggered by an unauthenticated, network‑based attacker without privileged access, the vulnerability results in a denial‑of‑service condition that affects the entire system.
Affected Systems
The vulnerability impacts Juniper Networks’ Junos OS on MX Series with SPC3, SRX5k Series with SPC3, SRX1600, SRX2300, SRX4000, and vSRX Series. All firmware versions prior to 23.2R2‑S4, 23.4R2‑S5, and 24.2R2 are affected. The fixed releases are 22.4R3‑S8, 23.2R2‑S4, 23.4R2‑S5, 24.2R2, 24.4R1, and any subsequent releases.
Risk and Exploitability
The CVSS score of 8.2 reflects a high‑severity flaw, while the EPSS score of <1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by initiating a TCP connection to the device and responding with the precise packet that triggers the crash, a scenario that can occur in various network service contexts such as ALG, SSL proxy, UTM, RTLOG, AppQoE probing, AAMW, ICAP, or URL filtering. The impact is a system‑wide service interruption until the PFE restarts automatically.
OpenCVE Enrichment