Impact
An Improper Restriction of Communication in Juniper Networks Junos OS Evolved lets an unauthenticated network attacker reach a process that should be limited to internal communication. By connecting to an unintentionally exposed port, the attacker can access the device’s license management subsystem and trigger license exhaustion, which can degrade or stop services. This weakness aligns with CWE‑923, indicating that an open channel was not adequately constrained.
Affected Systems
The vulnerability is present in all Junos OS Evolved releases earlier than 23.2R2‑EVO. Devices running any firmware version prior to 23.2R2‑EVO are vulnerable until they are upgraded to a supported release.
Risk and Exploitability
The CVSS score of 6.9 reflects moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the bug is not listed in the CISA KEV catalog. The vector is a network‑based, unauthenticated connection to the exposed port; no user interaction or elevated privileges are required. If exploited, the attacker can deplete licensed resources and cause a denial of service.
OpenCVE Enrichment