PT-2026-56977 · Juniper Networks · Junos

CVE-2026-57023

·

Published

2026-07-09

·

Updated

2026-07-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Junos OS on MX Series with SPC3 and SRX Series versions 23.4 through 23.4R2-S7 Junos OS on MX Series with SPC3 and SRX Series versions 24.2 through 24.2R2-S4 Junos OS on MX Series with SPC3 and SRX Series versions 24.4 through 24.4R2-S3 Junos OS on MX Series with SPC3 and SRX Series versions 25.2 through 25.2R2
Description An improper validation of specified quantity in input within the TCP proxy plugin allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS). When the TCP proxy is active in a flow session to support Application Layer Gateways (ALGs), Advanced Anti-Malware, ICAP, or Unified Threat Management (UTM), a TCP packet containing a specifically malformed TCP header triggers a crash and restart of the flow processing daemon (flowd). This results in a complete service outage until the system automatically recovers.
Recommendations Update Junos OS on MX Series with SPC3 and SRX Series version 23.4 to 23.4R2-S7 or later. Update Junos OS on MX Series with SPC3 and SRX Series version 24.2 to 24.2R2-S4 or later. Update Junos OS on MX Series with SPC3 and SRX Series version 24.4 to 24.4R2-S3 or later. Update Junos OS on MX Series with SPC3 and SRX Series version 25.2 to 25.2R2 or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57023

Affected Products

Junos