← Back

CVE-2026-33781

nvd nist
Published: Apr 9, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.1
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X
Show more
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:XShow less
Source: sirt@juniper.net (Secondary)

Description

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX and QFX Series devices allow an unauthenticated, adjacent attacker to cause a complete Denial of Service (DoS). On EX4k, and QFX5k platforms configured as service-provider edge devices, if L2PT is enabled on the UNI and VSTP is enabled on NNI in VXLAN scenarios, receiving VSTP BPDUs on UNI leads to packet buffer allocation failures, resulting in the device to not pass traffic anymore until it is manually recovered with a restart.This issue affects Junos OS: * 24.4 releases before 24.4R2, * 25.2 releases before 25.2R1-S1, 25.2R2. This issue does not affect Junos OS releases before 24.4R1.

Affected (7)

Products: Juniper: Junos
1 product
Junos
Configuration A
7 vulnerable · 18 platform
Vulnerable SoftwareAffected Versions
Juniper
Version 24.4
Version 24.4 r1-s2
Version 24.4 r1-s3
Version 24.4 r1
Version 25.2
Version 25.2 r1
Version 25.2 r2
Running on/withPlatform Versions
Juniper
Ex4000
All versions
Juniper
Ex4100
All versions
Juniper
Ex4100 F
All versions
Juniper
Ex4100 H
All versions
Juniper
Ex4300
All versions
Juniper
Ex4400
All versions
Juniper
Ex4600
All versions
Juniper
Ex4650
All versions
Juniper
Qfx5110
All versions
Juniper
Qfx5120
All versions
Juniper
Qfx5130
All versions
Juniper
Qfx5200
All versions
Juniper
Qfx5210
All versions
Juniper
Qfx5220
All versions
Juniper
Qfx5230 64cd
All versions
Juniper
Qfx5240
All versions
Juniper
Qfx5241
All versions
Juniper
Qfx5700
All versions

References (1)

Source: sirt@juniper.net
MitigationVendor Advisory

Timeline

No history available yet.