PT-2026-56986 · Juniper Networks · Ex4400+5
CVE-2026-57032
·
Published
2026-07-09
·
Updated
2026-07-10
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions prior to 23.2R2-S7
Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions 23.4 prior to 23.4R2-S8
Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions 24.2 prior to 24.2R2-S5
Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions 24.4 prior to 24.4R2
Description
An improper handling of undefined parameters in the packet forwarding engine (pfe) allows an authenticated attacker with low privileges to cause a Denial-of-Service (DoS). This occurs when a request is made to subscribe to an unsupported telemetry sensor path via gRPC, which causes the Flexible PIC Concentrator (FPC) to crash. This results in a complete service outage until the module automatically restarts.
Recommendations
Update Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 to version 23.2R2-S7 or later.
Update Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions 23.4 to 23.4R2-S8 or later.
Update Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions 24.2 to 24.2R2-S5 or later.
Update Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions 24.4 to 24.4R2 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ex2300
Ex3400
Ex4000
Ex4100
Ex4400
Junos