Impact
An improper validation of SIP invite syntax in Junos OS’s SIP plugin allows an attacker to send a malformed SIP invite that causes the flowd crash triggers a restart of the flow processing system, leading to a complete denial of service until the device automatically recovers. The flaw is categorized as CWE‑1286 – Improper Validation of Syntactic Correctness of Input, and it requires no authentication or privileged access.
Affected Systems
Juniper Networks Junos OS running on MX Series with SPC3 and SRX Series in releases before 23.2R2‑S7, 23.4R2‑S8, 24.2R2‑S5, 24.4R2‑S4, 25.2R2, and 25.4R1‑S2 are vulnerable.
Risk and Exploitability
The CVSS score of 8.7 signals high severity. The EPSS score of <1% indicates a low but nonzero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw from any network host that can reach the SIP ALG on the affected device, typically over standard SIP ports. A single malformed SIP invite will crash the flow daemon and cause a system‑wide service outage until automatic recovery occurs.
OpenCVE Enrichment