Description
A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS).


When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed.




This issue affects Junos OS Evolved on QFX Series:


* all 23.2 versions, 
* 23.4 versions before 23.4R2-S7-EVO,
* 24.2 versions before 24.2R2-S5-EVO,
* 24.4 versions before 24.4R2-S3-EVO,
* 25.2 versions before 25.2R2-EVO.
Published: 2026-07-09
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing synchronization bug in Juniper Networks Junos OS Evolved’s flow collector handler for QFX Series can cause the evo-pfemand process to crash when the reachability state of an sFlow collector changes at the same time the sFlow thread accesses next-hop data. The crash stops all traffic forwarding until the system resets the process, resulting in a temporary denial of service. An adjacent, unauthenticated attacker can manipulate the collector reachability state to trigger the crash.

Affected Systems

The vulnerability affects Juniper Networks Junos OS Evolved on QFX Series. All released versions of 23.2, 23.4 prior to 23.4R2-S7-EVO, 24.2 prior to 24.2R2-S5-EVO, 24.4 prior to 24.4R2-S3-EVO, and 25.2 prior to 25.2R2-EVO are impacted.

Risk and Exploitability

The CVSS score of 6.0 indicates moderate severity. The EPSS score is less than 1%, implying a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Because the trigger depends on an external change to the reachability state of a nearby sFlow collector, an attacker with network proximity but no device credentials can succeed, making the risk relatively elevated for internal or adjacent adversaries.

Generated by OpenCVE AI on August 1, 2026 at 13:48 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 23.4R2-S7-EVO, 24.2R2-S5-EVO, 24.4R2-S3-EVO, 25.2R2-EVO, 25.4R1-EVO, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade to any Junos OS Evolved release that includes the fix, such as 23.4R2-S7-EVO, 24.2R2-S5-EVO, 24.4R2-S3-EVO, 25.2R2-EVO, 25.4R1-EVO, or any newer release.
  • Monitor system operational state and logs for any evo-pemand crashes and confirm automatic restarts are functioning.
  • Maintain awareness of vendor announcements; keep the device updated and verify that no unpatched devices remain in the network.

Generated by OpenCVE AI on August 1, 2026 at 13:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 11 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os Evolved
Vendors & Products Juniper Networks
Juniper Networks junos Os Evolved

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed. This issue affects Junos OS Evolved on QFX Series: * all 23.2 versions,  * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24.4R2-S3-EVO, * 25.2 versions before 25.2R2-EVO.
Title Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash
Weaknesses CWE-820
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/RE:M'}


Subscriptions

Juniper Junos Os Evolved Qfx10008 Qfx10016 Qfx5110 Qfx5120 Qfx5130 Qfx5140 Qfx5200 Qfx5210 Qfx5220 Qfx5230-64cd Qfx5240 Qfx5241 Qfx5250 Qfx5700
Juniper Networks Junos Os Evolved
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:45:20.380Z

Reserved: 2026-06-23T16:27:00.249Z

Link: CVE-2026-57029

cve-icon Vulnrichment

Updated: 2026-07-10T14:45:16.218Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-09T22:17:08.453

Modified: 2026-07-13T20:23:46.113

Link: CVE-2026-57029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T14:00:06Z

Weaknesses