Description
A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS).


When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed.




This issue affects Junos OS Evolved on QFX Series:


* all 23.2 versions, 
* 23.4 versions before 23.4R2-S7-EVO,
* 24.2 versions before 24.2R2-S5-EVO,
* 24.4 versions before 24.4R2-S3-EVO,
* 25.2 versions before 25.2R2-EVO.
Published: 2026-07-09
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing synchronization bug in Juniper Networks Junos OS Evolved’s flow collector handler for QFX Series can cause the evo‑pfemand process to crash when the reachability state of an sFlow collector changes at the same time the sFlow thread accesses next‑hop data. The crash stops all traffic forwarding until the system rests the process, resulting in a temporary denial of service. An adjacent, unauthenticated attacker can manipulate the collector reachability state to trigger the crash.

Affected Systems

The vulnerability affects Juniper Networks Junos OS Evolved on QFX Series. All released versions of 23.2, 23.4 prior to 23.4R2‑S7‑EVO, 24.2 prior to 24.2R2‑S5‑EVO, 24.4 prior to 24.4R2‑S3‑EVO, and 25.2 prior to 25.2R2‑EVO are impacted.

Risk and Exploitability

The CVSS score of 6.0 indicates moderate severity. The EPSS score is less than 1%, implying a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Because the trigger depends on an external change to the reachability state of a nearby sFlow collector, an attacker with network proximity but no device credentials can succeed, making the risk relatively elevated for internal or adjacent adversaries.

Generated by OpenCVE AI on July 29, 2026 at 11:50 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 23.4R2-S7-EVO, 24.2R2-S5-EVO, 24.4R2-S3-EVO, 25.2R2-EVO, 25.4R1-EVO, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade to any Junos OS Evolved release that includes the fix, such as 23.4R2‑S7‑EVO, 24.2R2‑S5‑EVO, 24.4R2‑S3‑EVO, 25.2R2‑EVO, 25.4R1‑EVO, or any newer release.
  • Monitor system operational state and logs for any evo‑pfemand crashes and confirm automatic restarts are functioning.
  • Maintain awareness of vendor announcements; keep the device updated and verify that no unpatched devices remain in the network.

Generated by OpenCVE AI on July 29, 2026 at 11:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 11 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os Evolved
Vendors & Products Juniper Networks
Juniper Networks junos Os Evolved

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed. This issue affects Junos OS Evolved on QFX Series: * all 23.2 versions,  * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24.4R2-S3-EVO, * 25.2 versions before 25.2R2-EVO.
Title Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash
Weaknesses CWE-820
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/RE:M'}


Subscriptions

Juniper Networks Junos Os Evolved
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:45:20.380Z

Reserved: 2026-06-23T16:27:00.249Z

Link: CVE-2026-57029

cve-icon Vulnrichment

Updated: 2026-07-10T14:45:16.218Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses