PT-2026-56983 · Juniper Networks · Junos Evolved
CVE-2026-57029
·
Published
2026-07-09
·
Updated
2026-07-10
CVSS v3.1
5.3
Medium
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Junos OS Evolved on QFX Series versions 23.2
Junos OS Evolved on QFX Series versions prior to 23.4R2-S7-EVO
Junos OS Evolved on QFX Series versions prior to 24.2R2-S5-EVO
Junos OS Evolved on QFX Series versions prior to 24.4R2-S3-EVO
Junos OS Evolved on QFX Series versions prior to 25.2R2-EVO
Description
A missing synchronization issue in the flow collector handler allows an adjacent, unauthenticated attacker to trigger a Denial-of-Service (DoS). The problem occurs when the reachability of an sFlow collector changes, causing a next-hop entry update. If this update happens simultaneously with the sFlow thread accessing the next-hop data, the
evo-pfemand process crashes, which disrupts all traffic forwarding until the process automatically restarts.Recommendations
Update Junos OS Evolved on QFX Series version 23.2 to a fixed release.
Update Junos OS Evolved on QFX Series to version 23.4R2-S7-EVO or later.
Update Junos OS Evolved on QFX Series to version 24.2R2-S5-EVO or later.
Update Junos OS Evolved on QFX Series to version 24.4R2-S3-EVO or later.
Update Junos OS Evolved on QFX Series to version 25.2R2-EVO or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos Evolved