Impact
A missing synchronization bug in Juniper Networks Junos OS Evolved’s flow collector handler for QFX Series can cause the evo‑pfemand process to crash when the reachability state of an sFlow collector changes at the same time the sFlow thread accesses next‑hop data. The crash stops all traffic forwarding until the system rests the process, resulting in a temporary denial of service. An adjacent, unauthenticated attacker can manipulate the collector reachability state to trigger the crash.
Affected Systems
The vulnerability affects Juniper Networks Junos OS Evolved on QFX Series. All released versions of 23.2, 23.4 prior to 23.4R2‑S7‑EVO, 24.2 prior to 24.2R2‑S5‑EVO, 24.4 prior to 24.4R2‑S3‑EVO, and 25.2 prior to 25.2R2‑EVO are impacted.
Risk and Exploitability
The CVSS score of 6.0 indicates moderate severity. The EPSS score is less than 1%, implying a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Because the trigger depends on an external change to the reachability state of a nearby sFlow collector, an attacker with network proximity but no device credentials can succeed, making the risk relatively elevated for internal or adjacent adversaries.
OpenCVE Enrichment