Impact
The flaw exists in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series. A specially crafted TCP packet with a malformed header bypasses input validation and causes the flow processing daemon (flowd) to crash. The crash forces a daemon restart and results in a temporary complete service outage until the system recovers automatically. The weakness is classified as an input validation vulnerability (CWE‑1284) and does not grant code execution or escalation.
Affected Systems
The vulnerability affects Junos OS on MX Series with SPC3 and SRX Series. All releases before 23.4R2‑S7, 24.2R2‑S4, 24.4R2‑S3, and 25.2R2 are impacted. Versions earlier than 23.4R1 are not vulnerable. Vendor Juniper Networks provides the fix in licensed releases 23.4R2‑S7, 24.2R2‑S4, 24.4R2‑S3, 25.2R2, 25.4R1, and all subsequent releases.
Risk and Exploitability
The vulnerability carries a high CVSS score of 8.7, indicating a severe denial‑of‑service impact. The EPSS score is below 1 %, meaning the likelihood of current exploitation is low, and the issue is not listed in the CISA KEV catalog. A malicious attacker with network access can send the malformed packet to a device where the TCP proxy is enabled for ALGs, Advanced Anti‑Malware, ICAP, or UTM, causing a crash that temporarily disrupts all services. The only protections are the vendor patch or network isolation, as no workaround exists.
OpenCVE Enrichment