Juniper Networks Junos OS
cpe:2.3:a:juniper:junos:*:*:*:*:*:*:*, +3 more
- < 21.2R3-S9
- >= 21.4, < 21.4R3-S9
- >= 22.2, < 22.2R3-S5
- >= 22.4, < 22.4R3-S6
- >= 23.2, < 23.2R2
- >= 23.4, < 23.4R2
A NULL pointer dereference vulnerability has been identified in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series. This vulnerability allows an attacker to send specific valid control traffic out of a Dual-Stack (DS) Lite tunnel, causing the flowd process to crash and resulting in a denial-of-service condition. The flowd process failure leads to a network outage that persists until the process is restarted. Continuous transmission of the specific control traffic can create a sustained denial-of-service condition.
Exploitation of this vulnerability causes a segmentation fault in the flowd process, leading to a network outage until the process is restarted. This disruption can be sustained through continuous triggering of the specific control traffic.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.