Juniper Networks Junos OS
cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*
- < 21.2R3
- >= 21.4, < 21.4R3-S10
- >= 22.2, < 22.2R3-S6
- >= 22.4, < 22.4R3-S5
- >= 23.2, < 23.2R2-S3
- >= 23.4, < 23.4R2-S3
- >= 24.2, < 24.2R2
A vulnerability in the packet forwarding engine of Juniper Networks Junos OS on MX Series has been identified, allowing an unauthenticated adjacent attacker to cause a denial-of-service condition. This vulnerability arises from a memory leak triggered by login and logout activities in subscriber management scenarios. The leaked memory accumulates over time, eventually causing the system to crash. The issue affects all versions prior to 21.2R3-S9, as well as specific ranges in versions 21.4, 22.2, 22.4, 23.2, 23.4, and 24.2.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the system to crash after the accumulated memory leak reaches a critical point.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.