Impact
A race condition in the packet forwarding engine of Juniper Junos OS on SRX Series devices allows an unauthenticated, network‑based attacker to set an excessively long timeout on flow sessions. When the timeout exceeds 10,000 seconds the flow cannot be cleared, causing an accumulation of inactive sessions. The backlog can grow to hundreds of thousands of sessions, stopping the device’s forwarding engine and eventually triggering a flowd core or requiring a reboot. The vulnerability originates from improper synchronization when setting the timeout, as identified by CWE‑362.
Affected Systems
Vendors: Juniper Networks. Product: Junos OS on SRX Series. Affected releases include 24.2 versions before 24.2R2‑S3, 24.4 versions before 24.4R2‑S1 and 24.4R2‑S2, and 25.2 versions before 25.2R1‑S2 and 25.2R2. The fix is contained in Junos OS 24.2R2‑S3, 24.4R2‑S1, 25.2R1‑S2, 25.2R2, 25.4R1, and all subsequent releases.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity of this flaw. The EPSS score of less than 1% shows that, at the time of analysis, the likelihood of exploitation is low but not negligible. The vulnerability is not listed in CISA’s KEV catalog. It can be triggered by any actor who can send traffic to the SRX device, as no authentication is required. The attack surface is limited to the network interface that accepts traffic; the attacker must be able to generate or flood flow sessions to trigger the race condition.
OpenCVE Enrichment