Kestrel
대시보드로 돌아가기
CVE-2026-57030MEDIUM· 5.9MITRENVD대응게시일: 2026. 07. 09.수정일: 2026. 07. 13.CNA: sirt@juniper.netAnalyzed

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
5.9medium

이론적 심각도 점수

EPSS
0.3%상위 80.4%

30일 내 악용 확률 예측

KEV
미등재

실측 악용 기록 없음

권장 대응 기한60일 이내CISA SSVC 기준

계획된 패치 주기 내 조치(60일 이내)

외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출

CVSS 벡터 · 메트릭

악용 경로
공격 벡터네트워크
공격 복잡도높음
필요 권한불필요
사용자 상호작용불필요
범위불변
영향
기밀성 영향없음
무결성 영향없음
가용성 영향높음
버전별 점수
CVSS 4.08.2HIGH· 악용성숙도 NOT_DEFINED
CVSS 3.15.9MEDIUM· 악용성 2.2· 영향도 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

약점 (CWE)

  • CWE-362

    경쟁 조건(Race Condition) — 동시 실행 타이밍 결함으로 상태가 깨짐.

상세 설명

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

As part of the stateful traffic processing on SRX Series devices flows are being established, and removed when not needed anymore. During the removal process the timeout of a flow should be set to 3 seconds and consequentially the flow should be removed shortly after. Due to a race condition occurring when setting the timeout there is a chance (the exact conditions are outside the attackers control) that the timeout is instead set to a very high value of larger than 10,000 seconds:

user@host> show security flow session | match timeout
Session ID: 98784248524, Policy name: PROD-FLOW/4, HA State: Active, Timeout: 85250, Session State: Valid

This will lead to an accumulation of flows which can be observed by an ever-increasing value of invalidated sessions in the output of 'show security flow session summary':

user@host> show security flow session summary | match invalid
Invalidated sessions: 216931These sessions can't be cleared manually with the 'clear security flow session' command, which will either lead to forwarding to stop (and the system needs to be manually recovered with a reboot) or to a flowd core and automatic reboot.

This issue affects Junos OS on SRX Series:

  • 24.2 versions before 24.2R2-S3,
  • 24.4 versions before 24.4R2-S1, 24.4R2-S2,
  • 25.2 versions before 25.2R1-S2, 25.2R2.

This issue does not affect releases earlier than 24.2R1;

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.

영향받는 제품·버전

  • juniper junos
    other
  • juniper junos
    other
  • juniper junos
    other
  • juniper junos
    other
  • juniper junos
    other
  • juniper junos
    other
  • juniper junos
    other
  • juniper junos
    other
  • juniper junos
    other
  • juniper junos
    other
  • juniper junos
    other
  • juniper junos
    other
  • juniper junos
    other
  • juniper junos
    other
  • juniper junos
    other
  • juniper srx1500
    other
  • juniper srx1600
    other
  • juniper srx2300
    other
  • juniper srx300
    other
  • juniper srx320
    other
  • juniper srx340
    other
  • juniper srx345
    other
  • juniper srx380
    other
  • juniper srx400
    other
  • juniper srx4100
    other
  • juniper srx4120
    other
  • juniper srx4200
    other
  • juniper srx4300
    other
  • juniper srx440
    other
  • juniper srx4600
    other
  • juniper srx4700
    other
  • juniper srx5400
    other
  • juniper srx5600
    other
  • juniper srx5800
    other

영향받는 구성 (CPE) 34

  • juniper junos 24.2cpe:2.3:o:juniper:junos:24.2:-:*:*:*:*:*:*
  • juniper junos 24.2cpe:2.3:o:juniper:junos:24.2:r1:*:*:*:*:*:*
  • juniper junos 24.2cpe:2.3:o:juniper:junos:24.2:r1-s1:*:*:*:*:*:*
  • juniper junos 24.2cpe:2.3:o:juniper:junos:24.2:r1-s2:*:*:*:*:*:*
  • juniper junos 24.2cpe:2.3:o:juniper:junos:24.2:r2:*:*:*:*:*:*
  • juniper junos 24.2cpe:2.3:o:juniper:junos:24.2:r2-s1:*:*:*:*:*:*
  • juniper junos 24.2cpe:2.3:o:juniper:junos:24.2:r2-s2:*:*:*:*:*:*
  • juniper junos 24.4cpe:2.3:o:juniper:junos:24.4:-:*:*:*:*:*:*
  • juniper junos 24.4cpe:2.3:o:juniper:junos:24.4:r1:*:*:*:*:*:*
  • juniper junos 24.4cpe:2.3:o:juniper:junos:24.4:r1-s2:*:*:*:*:*:*
  • juniper junos 24.4cpe:2.3:o:juniper:junos:24.4:r1-s3:*:*:*:*:*:*
  • juniper junos 24.4cpe:2.3:o:juniper:junos:24.4:r2:*:*:*:*:*:*
  • juniper junos 25.2cpe:2.3:o:juniper:junos:25.2:-:*:*:*:*:*:*
  • juniper junos 25.2cpe:2.3:o:juniper:junos:25.2:r1:*:*:*:*:*:*
  • juniper junos 25.2cpe:2.3:o:juniper:junos:25.2:r1-s1:*:*:*:*:*:*
  • juniper srx1500cpe:2.3:h:juniper:srx1500:-:*:*:*:*:*:*:*
  • juniper srx1600cpe:2.3:h:juniper:srx1600:-:*:*:*:*:*:*:*
  • juniper srx2300cpe:2.3:h:juniper:srx2300:-:*:*:*:*:*:*:*
  • juniper srx300cpe:2.3:h:juniper:srx300:-:*:*:*:*:*:*:*
  • juniper srx320cpe:2.3:h:juniper:srx320:-:*:*:*:*:*:*:*
  • juniper srx340cpe:2.3:h:juniper:srx340:-:*:*:*:*:*:*:*
  • juniper srx345cpe:2.3:h:juniper:srx345:-:*:*:*:*:*:*:*
  • juniper srx380cpe:2.3:h:juniper:srx380:-:*:*:*:*:*:*:*
  • juniper srx400cpe:2.3:h:juniper:srx400:-:*:*:*:*:*:*:*
  • juniper srx4100cpe:2.3:h:juniper:srx4100:-:*:*:*:*:*:*:*
  • juniper srx4120cpe:2.3:h:juniper:srx4120:-:*:*:*:*:*:*:*
  • juniper srx4200cpe:2.3:h:juniper:srx4200:-:*:*:*:*:*:*:*
  • juniper srx4300cpe:2.3:h:juniper:srx4300:-:*:*:*:*:*:*:*
  • juniper srx440cpe:2.3:h:juniper:srx440:-:*:*:*:*:*:*:*
  • juniper srx4600cpe:2.3:h:juniper:srx4600:-:*:*:*:*:*:*:*
  • juniper srx4700cpe:2.3:h:juniper:srx4700:-:*:*:*:*:*:*:*
  • juniper srx5400cpe:2.3:h:juniper:srx5400:-:*:*:*:*:*:*:*
  • juniper srx5600cpe:2.3:h:juniper:srx5600:-:*:*:*:*:*:*:*
  • juniper srx5800cpe:2.3:h:juniper:srx5800:-:*:*:*:*:*:*:*

참고 자료 1

링크 내용 불러오는 중…