CVE-2026-57029
בינונית 5.3
תיאור (מקור, אנגלית)
A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed. This issue affects Junos OS Evolved on QFX Series: * all 23.2 versions, * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24.4R2-S3-EVO, * 25.2 versions before 25.2R2-EVO.
מדדים
- CVSS 3.1
-
5.3 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H - CVSS 4.0
-
6.0 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-18/8/2026
- CWE
- CWE-820
מוצרים מושפעים
juniper: junos os evolved; juniper: qfx10008; juniper: qfx10016; juniper: qfx5110; juniper: qfx5120; juniper: qfx5130; juniper: qfx5140; juniper: qfx5200; juniper: qfx5210; juniper: qfx5220; juniper: qfx5230-64cd; juniper: qfx5240; juniper: qfx5241; juniper: qfx5250; juniper: qfx5700
קישורים
- https://supportportal.juniper.net/JSA110089 Vendor Advisory