Executive brief
A vulnerability in Juniper Networks MX Series routers can allow an attacker on the same local network to cause a complete service outage. By triggering specific network events, an attacker can overwhelm the device's processing engine, causing the hardware to crash and restart. This results in a total loss of connectivity and network services until the system recovers.
Technical details
An 'Unchecked Input for Loop Condition' vulnerability (CWE-606) exists in the Packet Forwarding Engine (PFE) of Junos OS on MX Series devices. Micro-BFD session flaps generate up/down events that are queued by the PFEMAN process; in Virtual-Chassis scenarios with locality-bias configured, processing these events is computationally expensive. Continuous flapping prevents PFEMAN from completing its queue, leading to a watchdog timer expiration and a subsequent crash and restart of the Flexible PIC Concentrator (FPC). The issue is restricted to MX series FPCs up to and including MPC9. Patches have been released for affected Junos OS release branches.
Affected products
- Juniper Networks Junos OS All versions before 23.2R2-S7; 23.4 before 23.4R2-S8; 24.2 before 24.2R2-S4; 24.4 before 24.4R2-S3; 25.2 before 25.2R2
Timeline
- 2026-07-09: advisory: Initial publication of JSA110075