Impact
A missing release of memory after its effective lifetime in the packet forwarding engine of Junos OS leads to a memory leak. An unauthenticated adjacent attacker can trigger the flaw by sending multicast traffic through a Virtual Chassis configuration that has sFlow enabled. The accumulated leak ultimately causes the Flexible PIC Container to crash and reboot, resulting in a denial‑of‑service condition for the device.
Affected Systems
Juniper Networks Junos OS on EX4100 Series and EX4400 Series appliances. Affected releases include all versions before 23.2R2‑S7, 23.4 editions before 23.4R2‑S7, 24.2 editions before 24.2R2‑S4, and 24.4 editions before 24.4R2.
Risk and Exploitability
The CVSS score of 7.1 places the issue in the moderate‑to‑high severity range, while an EPSS score of < 1% indicates a very low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog. Exploitation requires only network adjacency and sFlow enabled in a Virtual Chassis; no authenticated access is needed. The attack path involves sending multicast packets that are forwarded between chassis members, provoking the memory leak observable by monitoring buffer values in the 'show chassis fpc' output, which eventually forces a device reboot and disrupts availability.
OpenCVE Enrichment