Impact
A Return of Pointer Value Outside of Expected Range vulnerability (CWE-466) in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker with CLI access to issue a specific 'show l2-learning' or 'show ethernet-switching' command. On EX Series, QFX Series, or MX Series devices, the vulnerable command triggers an l2ald crash, resulting in a denial of all layer-2 services until the process automatically restarts. The impact is a temporary service outage with no compromise of confidentiality or integrity.
Affected Systems
The vulnerability impacts Juniper Networks Junos OS and Junos OS Evolved on EX Series, QFX Series, and MX Series routers. For Junos OS, all releases before 23.2R2-S7, all 23.4 releases before 23.4R2-S7, all 24.2 releases before 24.2R2, and all 24.4 releases before 24.4R1-S2 are affected. For Junos OS Evolved, all releases before 23.2R2-S7-EVO, all 23.4 releases before 23.4R2-S8-EVO, all 24.2 releases before 24.2R2-EVO, and all 24.4 releases before 24.4R1-S3-EVO are impacted.
Risk and Exploitability
The CVSS score of 6.8 places this bug in the moderate severity range. The EPSS score is < 1%, indicating a very low likelihood of exploitation. A local, low-privileged attacker who has access to the CLI must first obtain such access before issuing the vulnerable command. Once executed, the l2ald crash occurs immediately, resulting in a brief service outage until automatic recovery. Limiting CLI access to trusted hosts and administrators reduces the attack surface and overall risk.
OpenCVE Enrichment