PT-2026-56977 · Juniper Networks · Junos
CVE-2026-57023
·
Published
2026-07-09
·
Updated
2026-07-23
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Junos OS on MX Series with SPC3 and SRX Series versions 23.4 through 23.4R2-S7
Junos OS on MX Series with SPC3 and SRX Series versions 24.2 through 24.2R2-S4
Junos OS on MX Series with SPC3 and SRX Series versions 24.4 through 24.4R2-S3
Junos OS on MX Series with SPC3 and SRX Series versions 25.2 through 25.2R2
Description
An improper validation of specified quantity in input within the TCP proxy plugin allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS). When the TCP proxy is active in a flow session to support Application Layer Gateways (ALGs), Advanced Anti-Malware, ICAP, or Unified Threat Management (UTM), a TCP packet containing a specifically malformed TCP header triggers a crash and restart of the flow processing daemon (
flowd). This results in a complete service outage until the system automatically recovers.Recommendations
Update Junos OS on MX Series with SPC3 and SRX Series version 23.4 to 23.4R2-S7 or later.
Update Junos OS on MX Series with SPC3 and SRX Series version 24.2 to 24.2R2-S4 or later.
Update Junos OS on MX Series with SPC3 and SRX Series version 24.4 to 24.4R2-S3 or later.
Update Junos OS on MX Series with SPC3 and SRX Series version 25.2 to 25.2R2 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos