Impact
The vulnerability is a misuse of incorrectly‑resolved names or references in the URL filtering plugin of Junos OS on MX Series routers. A specially formatted URL that the filtering logic misinterprets allows the request to be forwarded and provides access to downstream resources that the organization expected to be blocked. This flaw permits unauthorized transmission of data and potential compromise of assets that rely on web filtering for protection.
Affected Systems
Affected systems are Juniper Networks Junos OS running on MX Series routers. All versions prior to Junos OS 23.2R2‑S7, 23.4R2‑S8, 24.2R2‑S5, 24.4R2‑S4, 25.2R2‑S1, 25.4R1‑S2, 25.4R2, or any earlier release are vulnerable. The vulnerability does not exist in later versions that include the security updates listed by Juniper.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score of less than 1 % shows that exploitation is considered unlikely at present. Because the flaw requires no authentication and is exploitable from the network, an attacker with access to the MX router’s northbound interface can bypass the firewall’s web filtering to reach otherwise unreachable services. The vulnerability is not listed in the CISA KEV catalog, and no workaround is available, so remediation must rely on applying the patch or mitigating the exposure until the patch is installed.
OpenCVE Enrichment