Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q958-7f7x-pmq4

Опубликовано: 10 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.8
CVSS3: 5.5

Описание

A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS).

On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted.

This issue affects EX Series, QFX Series, MX Series: Junos OS:

  • all versions before 23.2R2-S7,
  • 23.4 versions before 23.4R2-S7,
  • 24.2 versions before 24.2R2,
  • 24.4 versions before 24.4R1-S2.

Junos OS Evolved:

  • all versions before 23.2R2-S7-EVO,
  • 23.4 versions before 23.4R2-S8-EVO,
  • 24.2 versions before 24.2R2-EVO,
  • 24.4 versions before 24.4R1-S3-EVO.

A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS).

On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted.

This issue affects EX Series, QFX Series, MX Series: Junos OS:

  • all versions before 23.2R2-S7,
  • 23.4 versions before 23.4R2-S7,
  • 24.2 versions before 24.2R2,
  • 24.4 versions before 24.4R1-S2.

Junos OS Evolved:

  • all versions before 23.2R2-S7-EVO,
  • 23.4 versions before 23.4R2-S8-EVO,
  • 24.2 versions before 24.2R2-EVO,
  • 24.4 versions before 24.4R1-S3-EVO.

EPSS

Процентиль: 1%
0.00098
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-466

Связанные уязвимости

CVSS3: 5.5
nvd
2 месяца назад

A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted. This issue affects EX Series, QFX Series, MX Series: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2. Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions before 24.4R1-S3-EVO.

EPSS

Процентиль: 1%
0.00098
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-466