A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed. This issue affects Junos OS Evolved on QFX Series: * all 23.2 versions, * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24.4R2-S3-EVO, * 25.2 versions before 25.2R2-EVO.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
23.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:23.2:*:*:*:*:*:*:* | ||
23.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:23.4:-:*:*:*:*:*:* | ||
23.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:23.4:r1:*:*:*:*:*:* | ||
23.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:23.4:r1-s1:*:*:*:*:*:* | ||
23.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:23.4:r1-s2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.