Description
A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS).

On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted.

This issue affects EX Series, QFX Series, MX Series:
Junos OS:


* all versions before 23.2R2-S7,
* 23.4 versions before 23.4R2-S7,
* 24.2 versions before 24.2R2,
* 24.4 versions before 24.4R1-S2.



Junos OS Evolved:
* all versions before 23.2R2-S7-EVO,
* 23.4 versions before 23.4R2-S8-EVO,
* 24.2 versions before 24.2R2-EVO,
* 24.4 versions before 24.4R1-S3-EVO.
Published: 2026-07-09
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Return in the fileio library of Juniper Networks Junos OS and Junos OS Evolved. A local, low‑privileged attacker with access to the CLI can issue a specific 'show l2-learning' command on EX Series, QFX Series, or MX Series devices, causing the l2ald process a denial of all layer‑2 services until the process automatically restarts. The impact is a service outage but does not compromise confidentiality or integrity.

Affected Systems

The vulnerability impacts Juniper Networks Junos OS and Junos OS Evolved on EX Series, QFX Series, and MX Series routers. For Junos OS, all releases before 23.2R2-S7, all 23.4 releases before 23.4R2-S7, all 24.2 releases before 24.2R2, and all 24.4 releases before 24.4R1-S2 are affected. For Junos OS Evolved, all releases before 23.2R2-S7-EVO, all 23.4 releases before 23.4R2-S8-EVO, all 24.2 releases before 24.2R2-EVO, and all 24.4 releases before 24.4R1-S3-EVO are impacted.

Risk and Exploitability

The CVSS score of 6.8 places this bug in the moderate severity range. The EPSS score is < 1%, indicating a very low likelihood of exploitation. A local, low‑privileged attacker who has access to the CLI must first obtain such access before issuing the vulnerable command. Once executed, the l2ald crash occurs immediately, resulting in a brief service outage until automatic recovery. Limiting CLI access to trusted hosts and administrators reduces the attack surface and overall risk.

Generated by OpenCVE AI on July 29, 2026 at 11:52 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S7, 23.4R2-S7, 24.2R2, 24.4R1-S2, 24.4R2, 25.2R1, and all subsequent releases; Junos OS Evolved: 23.2R2-S7-EVO, 23.4R2-S8-EVO, 24.2R2-EVO, 24.4R1-S3-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue. To reduce the risk of exploitation use access lists or firewall filters to limit access to the CLI only from trusted hosts and administrators.


OpenCVE Recommended Actions

  • Apply a Junos OS update from 23.2R2-S7 or later, as appropriate, to address the l2ald crash.
  • Limit CLI access by configuring access control lists or firewall filters so that only trusted hosts and administrators can issue commands.
  • Continuously monitor system logs for l2ald restarts and verify that layer‑2 services resume after a crash.

Generated by OpenCVE AI on July 29, 2026 at 11:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Description A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted. This issue affects EX Series, QFX Series, MX Series: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2. Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions before 24.4R1-S3-EVO. A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted. This issue affects EX Series, QFX Series, MX Series: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2. Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions before 24.4R1-S3-EVO.
Title Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning' command causes l2ald crash Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning/ethernet-switching' command causes l2ald crash

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Juniper Networks junos Os Evolved
Vendors & Products Juniper Networks
Juniper Networks junos Os
Juniper Networks junos Os Evolved

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted. This issue affects EX Series, QFX Series, MX Series: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2. Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions before 24.4R1-S3-EVO.
Title Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning' command causes l2ald crash
Weaknesses CWE-466
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M'}


Subscriptions

Juniper Networks Junos Os Junos Os Evolved
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-16T08:26:17.852Z

Reserved: 2026-06-23T16:27:00.248Z

Link: CVE-2026-57025

cve-icon Vulnrichment

Updated: 2026-07-10T14:10:47.508Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-466

    Return of Pointer Value Outside of Expected Range