MEDIUM🇬🇧 English

CVE-2026-57029

CVSS 6.0v4.0pub. 2026-07-09upd. 2026-07-13

Luka Missing Synchronization w obsługiwaču flow collectora Juniper Networks Junos OS Evolved na serii QFX pozwala sąsiadującemu, nieuwierzytelnionemu atakującemu spowodować Denial-of-Service (DoS). Gdy zmienia się osiągalność collectora sFlow, odpowiedni wpis next-hop jest aktualizowany — jeśli ta aktualizacja nastąpi równocześnie z dostępem wątku sFlow do danych next-hop, proces evo-pfemand ulegnie awarii, wpływając na całe forwarding ruchu do momentu automatycznego restartu. Podatność dotyczy Junos OS Evolved na serii QFX we wszystkich wersjach 23.2, 23.4 przed 23.4R2-S7-EVO, 24.2 przed 24.2R2-S5-EVO, 24.4 przed 24.4R2-S3-EVO oraz 25.2 przed 25.2R2-EVO.

Pokaż oryginał (EN)

A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed. This issue affects Junos OS Evolved on QFX Series: * all 23.2 versions,  * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24.4R2-S3-EVO, * 25.2 versions before 25.2R2-EVO.

CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X
  • Juniper Junos Os Evolved

    OS
    Juniper
    23.223.424.224.425.2
  • Juniper Qfx10008

    HW
    Juniper
    wszystkie wersje
  • Juniper Qfx10016

    HW
    Juniper
    wszystkie wersje
  • Juniper Qfx5110

    HW
    Juniper
    wszystkie wersje
  • Juniper Qfx5120

    HW
    Juniper
    wszystkie wersje
  • Juniper Qfx5130

    HW
    Juniper
    wszystkie wersje
  • Juniper Qfx5140

    HW
    Juniper
    wszystkie wersje
  • Juniper Qfx5200

    HW
    Juniper
    wszystkie wersje
  • Juniper Qfx5210

    HW
    Juniper
    wszystkie wersje
  • Juniper Qfx5220

    HW
    Juniper
    wszystkie wersje
  • Juniper Qfx5230 64cd

    HW
    Juniper
    wszystkie wersje
  • Juniper Qfx5240

    HW
    Juniper
    wszystkie wersje
  • Juniper Qfx5241

    HW
    Juniper
    wszystkie wersje
  • Juniper Qfx5250

    HW
    Juniper
    wszystkie wersje
  • Juniper Qfx5700

    HW
    Juniper
    wszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Auth Bypass
CWE
Referencje

Powiązane podatności

CVE-2026-21902CRITICAL9.3PL ✓ten sam produkt

RCE jako root w Juniper Junos OS Evolved — błędne uprawnienia do krytycznego zasobu

CVE-2021-0211CRITICAL10.0PL ✓ten sam produkt

Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message

CVE-2019-0008CRITICAL9.8PL ✓ten sam produkt

Stack-based buffer overflow w Junos OS FXPC — RCE przez BGP/BFD

CVE-2019-0006CRITICAL9.8PL ✓ten sam produkt

RCE przez niezainicjowany wskaźnik funkcji w Juniper Junos OS (fxpc)

CVE-2026-33794HIGH8.2PL ✓ten sam produkt

DoS w Juniper Junos OS Evolved – awaria procesu evo-aftmand przy unilist ECMP