PT-2026-56986 · Juniper Networks · Ex4400+5

CVE-2026-57032

·

Published

2026-07-09

·

Updated

2026-07-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions prior to 23.2R2-S7 Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions 23.4 prior to 23.4R2-S8 Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions 24.2 prior to 24.2R2-S5 Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions 24.4 prior to 24.4R2
Description An improper handling of undefined parameters in the packet forwarding engine (pfe) allows an authenticated attacker with low privileges to cause a Denial-of-Service (DoS). This occurs when a request is made to subscribe to an unsupported telemetry sensor path via gRPC, which causes the Flexible PIC Concentrator (FPC) to crash. This results in a complete service outage until the module automatically restarts.
Recommendations Update Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 to version 23.2R2-S7 or later. Update Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions 23.4 to 23.4R2-S8 or later. Update Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions 24.2 to 24.2R2-S5 or later. Update Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 versions 24.4 to 24.4R2 or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57032

Affected Products

Ex2300
Ex3400
Ex4000
Ex4100
Ex4400
Junos