PT-2026-56967 · Juniper Networks · Junos Evolved
CVE-2026-33803
·
Published
2026-07-09
·
Updated
2026-07-10
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Junos OS Evolved versions prior to 23.2R2-S7-EVO
Junos OS Evolved versions 23.4 through 23.4R2-S8-EVO
Junos OS Evolved versions 24.2 through 24.2R2-S5-EVO
Junos OS Evolved versions 24.4 through 24.4R2-S4-EVO
Junos OS Evolved versions 25.2 through 25.2R2-S1-EVO
Junos OS Evolved versions 25.4 through 25.4R1-S2-EVO
Description
An improper restriction of communication channel to intended endpoints allows an unauthenticated, network-based attacker to cause limited information disclosure and impact device availability. Due to incorrect initialization, a process intended for internal communication is accessible over the network via an open port, resulting in inadvertent device exposure and increased CPU consumption while processing ingress packets.
Recommendations
Update to version 23.2R2-S7-EVO or later.
Update to version 23.4R2-S8-EVO or later.
Update to version 24.2R2-S5-EVO or later.
Update to version 24.4R2-S4-EVO or later.
Update to version 25.2R2-S1-EVO or later.
Update to version 25.4R1-S2-EVO or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos Evolved