PT-2026-56928 · Juniper Networks · Junos
CVE-2026-33800
·
Published
2026-07-09
·
Updated
2026-07-20
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Junos OS on MX Series versions prior to 23.2R2-S7
Junos OS on MX Series versions 23.4 through 23.4R2-S7
Junos OS on MX Series versions 24.2 through 24.2R2-S3
Junos OS on MX Series versions 24.4 through 24.4R2-S2
Junos OS on MX Series versions 25.2 through 25.2R1
Description
An unchecked input for loop condition in the Packet Forwarding Engine (pfe) allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). In Virtual-Chassis (VC) scenarios with locality-bias configured, Micro-BFD session flaps generate up/down events that are queued by PFEMAN for processing. If these sessions flap continuously, the processing time per event prevents PFEMAN from completing its queue. This leads to the expiration of the PFEMAN watchdog timer, causing the Flexible PIC Concentrator (FPC) to crash and restart, resulting in a complete service outage. This issue specifically affects MX series FPCs up to and including MPC9.
Recommendations
Update to version 23.2R2-S7 or later.
Update to version 23.4R2-S8 or later.
Update to version 24.2R2-S4 or later.
Update to version 24.4R2-S3 or later.
Update to version 25.2R2 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos