PT-2026-56978 · Juniper Networks · Junos
CVE-2026-57024
·
Published
2026-07-09
·
Updated
2026-07-10
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Junos OS on MX with SPC3 and SRX Series versions prior to 23.2R2-S7
Junos OS on MX with SPC3 and SRX Series versions 23.4 through 23.4R2-S5
Junos OS on MX with SPC3 and SRX Series versions 24.2 through 24.2R2-S2
Junos OS on MX with SPC3 and SRX Series versions 24.4 through 24.4R2-S3
Junos OS on MX with SPC3 and SRX Series versions 25.2 through 25.2R1-S0
Description
A Use of Multiple Resources with Duplicate Identifier issue in the IKE daemon (iked) allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On devices configured for VPN service, a high volume of failed VPN negotiations can trigger a peer index rollover. This causes new peers to be assigned index values already in use, leading to repeated crashes of the
iked process. Consequently, the system fails to establish new VPN connections or rekey existing ones, requiring a reboot to restore service.Recommendations
Update to version 23.2R2-S7 or later.
Update to version 23.4R2-S6 or later.
Update to version 24.2R2-S3 or later.
Update to version 24.4R2-S4 or later.
Update to version 25.2R1-S1 or later.
As a mitigation measure, use the
kmd process instead of iked to avoid exposure to this issue.Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos