PT-2026-56975 · Juniper Networks · Junos
CVE-2026-57021
·
Published
2026-07-09
·
Updated
2026-07-10
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Junos OS on SRX Series versions prior to 23.2R2-S7
Junos OS on SRX Series versions prior to 23.4R2-S8
Junos OS on SRX Series versions prior to 24.2R2-S4
Junos OS on SRX Series versions prior to 24.4R2-S4
Junos OS on SRX Series versions prior to 25.2R2
Junos OS on SRX Series versions prior to 25.4R1-S1
Junos OS on SRX Series versions prior to 25.4R2
Description
An out-of-bounds write in the http-gatekeeper (http-gk) allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). This occurs when a device is configured for remote-access VPN with pre-logon compliance check. By sending specifically formatted requests, an attacker can trigger a crash of the http-gk process, resulting in the unavailability of services dependent on the
system services web-management configuration, such as J-Web, remote access VPN, and firewall authentication, until the process restarts automatically.Recommendations
Update to version 23.2R2-S7 or later.
Update to version 23.4R2-S8 or later.
Update to version 24.2R2-S4 or later.
Update to version 24.4R2-S4 or later.
Update to version 25.2R2 or later.
Update to version 25.4R1-S1 or later.
Update to version 25.4R2 or later.
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos