CyberRota Analysis
AI-GeneratedA vulnerability in the fileio library of Juniper Networks' Junos OS and Junos OS Evolved allows a low-privileged local attacker to execute specific commands that trigger a crash in the l2ald process, resulting in a Denial-of-Service (DoS) condition for all Layer 2 services. This issue affects various EX Series, QFX Series, and MX Series devices running specific versions of the affected operating systems. Network administrators and security teams managing these devices should prioritize applying the relevant updates to mitigate potential service disruptions.
Original NVD Description
A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted. This issue affects EX Series, QFX Series, MX Series: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2. Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions before 24.4R1-S3-EVO.
Related CVEs
Other vulnerabilities affecting the same vendor(s)