AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-57029

MEDIUM · CVSS 5.3 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

A missing synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to trigger a Denial-of-Service (DoS) by causing the evo-pfemand process to crash during simultaneous updates to the next-hop entry. This impacts all traffic forwarding until the process restarts, potentially disrupting network operations. Organizations using affected versions of Junos OS Evolved should prioritize patching to mitigate this risk.

CVE
CVE-2026-57029
Severity
MEDIUM
CVSS
5.3
EPSS
0.12%

Original NVD Description

A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed. This issue affects Junos OS Evolved on QFX Series: * all 23.2 versions,  * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24.4R2-S3-EVO, * 25.2 versions before 25.2R2-EVO.

Related CVEs

Other vulnerabilities affecting the same vendor(s)