MEDIUM🇵🇱 Wersja polska

CVE-2026-57029

CVSS 6.0v4.0pub. 2026-07-09upd. 2026-07-13

A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed. This issue affects Junos OS Evolved on QFX Series: * all 23.2 versions,  * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24.4R2-S3-EVO, * 25.2 versions before 25.2R2-EVO.

CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X
  • Juniper Junos Os Evolved

    OS
    Juniper
    23.223.424.224.425.2
  • Juniper Qfx10008

    HW
    Juniper
    all versions
  • Juniper Qfx10016

    HW
    Juniper
    all versions
  • Juniper Qfx5110

    HW
    Juniper
    all versions
  • Juniper Qfx5120

    HW
    Juniper
    all versions
  • Juniper Qfx5130

    HW
    Juniper
    all versions
  • Juniper Qfx5140

    HW
    Juniper
    all versions
  • Juniper Qfx5200

    HW
    Juniper
    all versions
  • Juniper Qfx5210

    HW
    Juniper
    all versions
  • Juniper Qfx5220

    HW
    Juniper
    all versions
  • Juniper Qfx5230 64cd

    HW
    Juniper
    all versions
  • Juniper Qfx5240

    HW
    Juniper
    all versions
  • Juniper Qfx5241

    HW
    Juniper
    all versions
  • Juniper Qfx5250

    HW
    Juniper
    all versions
  • Juniper Qfx5700

    HW
    Juniper
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-21902CRITICAL9.3PL ✓same product

RCE jako root w Juniper Junos OS Evolved — błędne uprawnienia do krytycznego zasobu

CVE-2021-0211CRITICAL10.0PL ✓same product

Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message

CVE-2019-0008CRITICAL9.8PL ✓same product

Stack-based buffer overflow w Junos OS FXPC — RCE przez BGP/BFD

CVE-2019-0006CRITICAL9.8PL ✓same product

RCE przez niezainicjowany wskaźnik funkcji w Juniper Junos OS (fxpc)

CVE-2026-33794HIGH8.2PL ✓same product

DoS w Juniper Junos OS Evolved – awaria procesu evo-aftmand przy unilist ECMP