PT-2026-56973 · Juniper Networks · Junos
CVE-2026-57019
·
Published
2026-07-09
·
Updated
2026-07-10
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Junos OS on MX Series versions prior to 23.2R2-S6
Junos OS on MX Series versions 23.4 through 23.4R2-S7
Junos OS on MX Series versions 24.2 through 24.2R2-S4
Junos OS on MX Series versions 24.4 through 24.4R2-S4
Junos OS on MX Series versions 25.2 through 25.2R2
Description
An improper validation of specified quantity in input within the Packet Forwarding Engine (pfe) allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). When a specific packet is received from a device in the same broadcast domain, the system calculates the packet size incorrectly, causing packet processing to fail. This triggers a Flexible PIC Concentrator (FPC) major error, resulting in an FPC reset that impacts traffic until the FPC automatically recovers. This issue occurs during MAP-T scenarios or when non-IP traffic is encapsulated in IP, such as MPLS over GRE.
Recommendations
Update Junos OS on MX Series to version 23.2R2-S6 or later.
Update Junos OS on MX Series 23.4 to version 23.4R2-S7 or later.
Update Junos OS on MX Series 24.2 to version 24.2R2-S4 or later.
Update Junos OS on MX Series 24.4 to version 24.4R2-S4 or later.
Update Junos OS on MX Series 25.2 to version 25.2R2 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos