PT-2026-56973 · Juniper Networks · Junos

CVE-2026-57019

·

Published

2026-07-09

·

Updated

2026-07-10

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Junos OS on MX Series versions prior to 23.2R2-S6 Junos OS on MX Series versions 23.4 through 23.4R2-S7 Junos OS on MX Series versions 24.2 through 24.2R2-S4 Junos OS on MX Series versions 24.4 through 24.4R2-S4 Junos OS on MX Series versions 25.2 through 25.2R2
Description An improper validation of specified quantity in input within the Packet Forwarding Engine (pfe) allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). When a specific packet is received from a device in the same broadcast domain, the system calculates the packet size incorrectly, causing packet processing to fail. This triggers a Flexible PIC Concentrator (FPC) major error, resulting in an FPC reset that impacts traffic until the FPC automatically recovers. This issue occurs during MAP-T scenarios or when non-IP traffic is encapsulated in IP, such as MPLS over GRE.
Recommendations Update Junos OS on MX Series to version 23.2R2-S6 or later. Update Junos OS on MX Series 23.4 to version 23.4R2-S7 or later. Update Junos OS on MX Series 24.2 to version 24.2R2-S4 or later. Update Junos OS on MX Series 24.4 to version 24.4R2-S4 or later. Update Junos OS on MX Series 25.2 to version 25.2R2 or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57019

Affected Products

Junos