HIGH🇵🇱 Wersja polska

CVE-2026-33800

CVSS 7.1v4.0pub. 2026-07-09upd. 2026-08-26

An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD session flaps generate respective up/down events which are queued by PFEMAN for processing. Especially in a Virtual-Chassis (VC) scenario with locality‑bias configured, processing takes a significant amount of time for each event. If these sessions keep flapping, new events are constantly added, and in turn PFEMAN never completes processing these events. This results in the PFEMAN watchdog timer expiring, which causes the FPC to crash and restart, representing a complete service outage. This issue only affects MX series FPCs up to and including MPC9, and LC2101/2103 and LC480. It does not affect MPC10/11, LC4800/9600, and MX304. This issue affects Junos OS on MX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R2.

CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X
  • Juniper Junos

    OS
    Juniper
    23.223.424.224.425.2< 23.2
  • Juniper Lc2101

    HW
    Juniper
    all versions
  • Juniper Lc2103

    HW
    Juniper
    all versions
  • Juniper Lc4800

    HW
    Juniper
    all versions
  • Juniper Mpc1

    HW
    Juniper
    all versions
  • Juniper Mpc1e

    HW
    Juniper
    all versions
  • Juniper Mpc1e Q

    HW
    Juniper
    all versions
  • Juniper Mpc1 Q

    HW
    Juniper
    all versions
  • Juniper Mpc2

    HW
    Juniper
    all versions
  • Juniper Mpc2e

    HW
    Juniper
    all versions
  • Juniper Mpc2e Eq

    HW
    Juniper
    all versions
  • Juniper Mpc2e Ng

    HW
    Juniper
    all versions
  • Juniper Mpc2e Ng Q

    HW
    Juniper
    all versions
  • Juniper Mpc2e P

    HW
    Juniper
    all versions
  • Juniper Mpc2 Eq

    HW
    Juniper
    all versions
  • Juniper Mpc2e Q

    HW
    Juniper
    all versions
  • Juniper Mpc2 Q

    HW
    Juniper
    all versions
  • Juniper Mpc3e

    HW
    Juniper
    all versions
  • Juniper Mpc3e 3d Ng

    HW
    Juniper
    all versions
  • Juniper Mpc3e 3d Ng Q

    HW
    Juniper
    all versions
  • Juniper Mpc6e

    HW
    Juniper
    all versions
  • Juniper Mpc7e 10g

    HW
    Juniper
    all versions
  • Juniper Mpc7e Mrate

    HW
    Juniper
    all versions
  • Juniper Mpc8e

    HW
    Juniper
    all versions
  • Juniper Mpc9e

    HW
    Juniper
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-36845CRITICAL9.8⚠ KEVPL ✓same product

RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)

CVE-2024-21591CRITICAL9.8PL ✓same product

Out-of-bounds Write w J-Web Juniper Junos OS — RCE z uprawnieniami root

CVE-2021-0248CRITICAL10.0PL ✓same product

Hard-coded Credentials w Juniper Junos OS na urządzeniach NFX Series

CVE-2021-0254CRITICAL9.8PL ✓same product

Buffer overflow w usłudze overlayd Juniper Junos OS — RCE i DoS

CVE-2021-0211CRITICAL10.0PL ✓same product

Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message