CVE-2004-0468
Description
Memory leak in Juniper JUNOS PFE allows remote attackers to cause denial of service via crafted IPv6 packets, leading to device reboot.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Memory leak in Juniper JUNOS PFE allows remote attackers to cause denial of service via crafted IPv6 packets, leading to device reboot.
Vulnerability
A memory leak exists in the Juniper JUNOS Packet Forwarding Engine (PFE) when processing certain IPv6 packets. The vulnerability affects all JUNOS PFEs released after February 24, 2004, with IPv6 processing enabled [1][2]. The PFE is not derived from other code (e.g., FreeBSD), so the issue is specific to JUNOS [2].
Exploitation
A remote, unauthenticated attacker can trigger the memory leak by sending multiple specially crafted IPv6 packets to a vulnerable Juniper router [1][2]. No authentication or prior access is required; the attacker only needs network connectivity to the target device.
Impact
Successful exploitation causes memory exhaustion in the PFE, leading to a system reboot. Repeated attacks can force the router to reboot continuously, resulting in a denial of service (DoS) for the router and potentially disrupting network traffic [1][2].
Mitigation
Juniper has addressed this issue in JUNOS builds created after June 21, 2004 [1]. Users should upgrade to a fixed version. As a workaround, disabling IPv6 processing in the Packet Forwarding Engine can prevent exploitation [2]. No KEV listing is associated with this CVE.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.jpcert.or.jp/at/2004/at040009.txtnvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/658859nvdPatchThird Party AdvisoryUS Government Resource
- www.kb.cert.org/vuls/id/JSHA-6253CCnvdPatchVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/16548nvd
News mentions
0No linked articles in our index yet.