Executive brief
A vulnerability in Juniper Networks SRX Series firewalls could allow an unauthenticated attacker to crash the device's gatekeeper service. This component manages critical functions like remote-access VPNs and the J-Web management interface. An exploit would result in a temporary denial of service, making the firewall's management and VPN services unavailable until the system automatically restarts.
Technical details
An out-of-bounds write vulnerability exists in the http-gatekeeper (http-gk) process of Junos OS on SRX Series devices. The flaw is triggered when the device is configured for remote-access VPN with pre-logon compliance checks enabled. A network-based attacker can send specifically formatted requests to trigger the memory corruption, leading to a process crash. This crash impacts all services relying on the 'system services web-management' configuration, including J-Web, remote access VPN, and firewall authentication. The service remains unavailable until the http-gk process automatically restarts. Fixed versions have been released across multiple Junos OS release trains.
Affected products
- Juniper Networks Junos OS 23.2 versions before 23.2R2-S7, 23.4 versions before 23.4R2-S8, 24.2 versions before 24.2R2-S4, 24.4 versions before 24.4R2-S4, 25.2 versions before 25.2R2, 25.4 versions before 25.4R1-S1, 25.4R2.
Timeline
- 2026-07-09: advisory: Initial publication of JSA110081