PT-2026-56974 · Juniper Networks · Junos
CVE-2026-57020
·
Published
2026-07-09
·
Updated
2026-07-10
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Junos OS on QFX10000 Series versions prior to 23.2R2-S7
Junos OS on QFX10000 Series versions 23.4 through 23.4R2-S8
Junos OS on QFX10000 Series versions 24.2 through 24.2R2-S4
Junos OS on QFX10000 Series versions 24.4 through 24.4R2-S4
Description
An improper check for unusual or exceptional conditions in the packet forwarding engine (pfe) allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). In an EVPN-VxLAN scenario, sending IPv6 multicast traffic to the non-IRB interface of a spine switch triggers a flood of packets to other spines and all Ethernet Segment Identifier (ESI) leaf switches. This results in an endless forwarding loop that can saturate involved links and disrupt legitimate traffic.
Recommendations
Update to version 23.2R2-S7 or later.
Update to version 23.4R2-S8 or later.
Update to version 24.2R2-S4 or later.
Update to version 24.4R2-S4 or later.
Fix
DoS
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos