Impact
An Improper Check for Unusual or Exceptional Conditions flaw in the packet forwarding engine of Juniper Networks Junos OS on MX Series routers enables adjacent subscribers who connect through static interfaces to bypass all configured ingress firewall filters and bandwidth limitations. Because this flaw allows traffic from those subscribers to pass the router unchecked, the primary impact is that unfiltered or potentially malicious packets can reach the internal network, exposing it to security threats. This vulnerability is identified as CWE‑754.
Affected Systems
The affected systems are Juniper Networks Junos OS running on MX Series routers, specifically MPC10, MPC11, LC4800, LC9600, and MX304 models. Affected releases include all 23.2R2‑S1 through 23.2R2‑S6, all 23.4R2 releases before 23.4R2‑S7, all 24.2 releases prior to 24.2R2‑S3, all 24.4 releases before 24.4R2‑S2, and all 25.2 releases older than 25.2R2. Versions released after these thresholds are not affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability, and the EPSS score of less than 1 % suggests exploitation is currently unlikely. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need direct local access to an adjacent subscriber interface configured with a static address on the same MX device; the attack path does not permit remote exploitation. Thus, the attack surface is limited, but the vulnerability permits unfiltered traffic into the network, representing a tangible risk to confidentiality and integrity of network traffic.
OpenCVE Enrichment