Impact
A Return in the fileio library of Juniper Networks Junos OS and Junos OS Evolved. A local, low‑privileged attacker with access to the CLI can issue a specific 'show l2-learning' command on EX Series, QFX Series, or MX Series devices, causing the l2ald process a denial of all layer‑2 services until the process automatically restarts. The impact is a service outage but does not compromise confidentiality or integrity.
Affected Systems
The vulnerability impacts Juniper Networks Junos OS and Junos OS Evolved on EX Series, QFX Series, and MX Series routers. For Junos OS, all releases before 23.2R2-S7, all 23.4 releases before 23.4R2-S7, all 24.2 releases before 24.2R2, and all 24.4 releases before 24.4R1-S2 are affected. For Junos OS Evolved, all releases before 23.2R2-S7-EVO, all 23.4 releases before 23.4R2-S8-EVO, all 24.2 releases before 24.2R2-EVO, and all 24.4 releases before 24.4R1-S3-EVO are impacted.
Risk and Exploitability
The CVSS score of 6.8 places this bug in the moderate severity range. The EPSS score is < 1%, indicating a very low likelihood of exploitation. A local, low‑privileged attacker who has access to the CLI must first obtain such access before issuing the vulnerable command. Once executed, the l2ald crash occurs immediately, resulting in a brief service outage until automatic recovery. Limiting CLI access to trusted hosts and administrators reduces the attack surface and overall risk.
OpenCVE Enrichment