PT-2026-56928 · Juniper Networks · Junos

CVE-2026-33800

·

Published

2026-07-09

·

Updated

2026-07-20

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Junos OS on MX Series versions prior to 23.2R2-S7 Junos OS on MX Series versions 23.4 through 23.4R2-S7 Junos OS on MX Series versions 24.2 through 24.2R2-S3 Junos OS on MX Series versions 24.4 through 24.4R2-S2 Junos OS on MX Series versions 25.2 through 25.2R1
Description An unchecked input for loop condition in the Packet Forwarding Engine (pfe) allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). In Virtual-Chassis (VC) scenarios with locality-bias configured, Micro-BFD session flaps generate up/down events that are queued by PFEMAN for processing. If these sessions flap continuously, the processing time per event prevents PFEMAN from completing its queue. This leads to the expiration of the PFEMAN watchdog timer, causing the Flexible PIC Concentrator (FPC) to crash and restart, resulting in a complete service outage. This issue specifically affects MX series FPCs up to and including MPC9.
Recommendations Update to version 23.2R2-S7 or later. Update to version 23.4R2-S8 or later. Update to version 24.2R2-S4 or later. Update to version 24.4R2-S3 or later. Update to version 25.2R2 or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33800

Affected Products

Junos