An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-privileged attacker to bring down an interface, leading to a Denial-of-Service.Users with "view" permissions can run a specific request interface command which allows the user to shut down the interface.
This issue affects Junos OS:
The following software releases have been updated to resolve this specific issue: 21.2R3-S9, 21.4R3-S11, 22.2R3-S7, 22.4R3-S7, 23.2R2-S4, 23.4R2-S5, 24.2R2-S1, 24.4R1-S3, 24.4R2, 25.2R1, and all subsequent releases.
This issue is being tracked as 1848754 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Utilize CLI authorization to disallow execution of the 'request interface' command.Use access lists or firewall filters to limit access to the CLI only from trusted hosts and administrators.
2025-07-09: Initial Publication