Impact
A missing release of memory after its effective lifetime in the packet forwarding engine of Junos OS leads to a memory leak that can be exploited by an unauthenticated adjacent attacker. When sFlow is enabled in a Virtual Chassis configuration, multicast traffic received on one chassis member and forwarded to another causes the leak to accumulate, eventually crashing the Flexible PIC Container and forcing a reboot. This results in a denial‑of‑service condition for the affected appliance.
Affected Systems
Juniper Networks Junos OS on EX4100 and EX4400 Series devices. All releases prior to 23.2R2‑S7, 23.4R2‑S7, 24.2R2‑S4, and 24.4R2 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 places the vulnerability in the moderate‑to‑high severity range, while an EPSS score of less than 1 % indicates a very low probability of exploitation as of now. The flaw is not listed in the CISA KEV catalog. Exploitation requires only adjacency on the network and sFlow enabled in a Virtual Chassis; no authentication is needed. An attacker can trigger the flaw by sending multicast packets that are forwarded between chassis members, creating a memory leak observable through continuous growth of buffer values shown by the 'show chassis fpc' command, which ultimately forces a device reboot.
OpenCVE Enrichment