Impact
An authentication-based vulnerability in Juniper Networks Junos OS on EX Series switches allows a low-privilege user to cause a denial-of-service by subscribing to an unsupported telemetry sensor path with gRPC. The packet forwarding engine crashes, stopping the FXPC process and rendering the device unusable until the module restarts. The crash is triggered by an improper handling of undefined parameters and results in a complete service outage. The weakness is categorized as CWE-236, reflecting uncontrolled resource consumption leading to a crash.
Affected Systems
The vulnerability affects Juniper Networks Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 devices. All software versions before 23.2R2-S7, all 23.4 releases before 23.4R2-S8, all 24.2 releases before 24.2R2-S5, and all 24.4 releases before 24.4R2 are impacted.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity of denial of service. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attack requires authenticated access to the device via gRPC, implying that a threat actor must first gain low-privilege credentials or compromise an existing management session. Once authenticated, the attacker can send an unsupported sensor path request, crash the FXPC process, and disrupt traffic until the module recycles.
OpenCVE Enrichment