This issue occurs on Juniper Networks Junos OS devices which do not support Advanced Forwarding Interface (AFI) / Advanced Forwarding Toolkit (AFT). Devices using AFI and AFT are not exploitable to this issue. An improper initialization of memory in the packet forwarding architecture in Juniper Networks Junos OS non-AFI/AFT platforms which may lead to a Denial of Service (DoS) vulnerability being exploited when a genuine packet is received and inspected by non-AFT/AFI sFlow and when the device is also configured with firewall policers. This first genuine packet received and inspected by sampled flow (sFlow) through a specific firewall policer will cause the device to reboot. After the reboot has completed, if the device receives and sFlow inspects another genuine packet seen through a spec
The following software releases have been updated to resolve this specific issue: 17.4R2-S9, 17.4R3;18.2X75-D12, 18.2X75-D30, 18.1R3-S9, 18.2R3, 18.3R3, 18.4R1, and all subsequent releases.
Discontinue use of firewall policers. Or Discontinue use of sFlow. Or Both of the above. It is not required to discontinue both to mitigate the issue. There are no other available workarounds.
| Product | Vulnerable range | Fixed version | Advisory |
|---|---|---|---|
| Juniper Networks Junos OS | >=17.4<17.4R2-S9, 17.4R3 | 17.4R2-S9, 17.4R3 | advisory ↗ |
| Juniper Networks Junos OS | >=18.1<=18.1R3-S9 | 18.1R3-S9 | advisory ↗ |
| Juniper Networks Junos OS | >=18.2<18.2R3 | 18.2R3 | advisory ↗ |
| Juniper Networks Junos OS | >=18.2X75<18.2X75-D12, 18.2X75-D30 | 18.2X75-D12, 18.2X75-D30 | advisory ↗ |
| Juniper Networks Junos OS | >=18.3<18.3R3 | 18.3R3 | advisory ↗ |