CVE-2026-33781
7.1
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:XShow more
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:XShow less
Source: sirt@juniper.net (Secondary)
Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX and QFX Series devices allow an unauthenticated, adjacent attacker to cause a complete Denial of Service (DoS).
On EX4k, and QFX5k platforms configured as service-provider edge devices, if L2PT is enabled on the UNI and VSTP is enabled on NNI in VXLAN scenarios, receiving VSTP BPDUs on UNI leads to packet buffer allocation failures, resulting in the device to not pass traffic anymore until it is manually recovered with a restart.This issue affects Junos OS:
* 24.4 releases before 24.4R2,
* 25.2 releases before 25.2R1-S1, 25.2R2.
This issue does not affect Junos OS releases before 24.4R1.
Affected (7)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 24.4 |
| Running on/with | Platform Versions |
|---|---|
Juniper Ex4000 | All versions |
Juniper Ex4100 | All versions |
Juniper Ex4100 F | All versions |
Juniper Ex4100 H | All versions |
Juniper Ex4300 | All versions |
Juniper Ex4400 | All versions |
Juniper Ex4600 | All versions |
Juniper Ex4650 | All versions |
Juniper Qfx5110 | All versions |
Juniper Qfx5120 | All versions |
Juniper Qfx5130 | All versions |
Juniper Qfx5200 | All versions |
Juniper Qfx5210 | All versions |
Juniper Qfx5220 | All versions |
Juniper Qfx5230 64cd | All versions |
Juniper Qfx5240 | All versions |
Juniper Qfx5241 | All versions |
Juniper Qfx5700 | All versions |
References (1)
Timeline
No history available yet.