Junglewise Threat Intelligence

CVE-2026-33799: Juniper Networks Junos OS out-of-bounds write in snmpd

CVE-2026-33799 · Severity: medium · CVSS 4.3 · Published 2026-07-09

Technologies: Juniper Networks Junos OS Evolved. Vendors: Juniper Networks.

Executive brief

A vulnerability in the monitoring software of Juniper Networks networking equipment could allow an authorized user to crash the system's monitoring service. By sending specific management queries, an attacker can cause the device to run out of memory, leading to a service restart. This prevents administrators from effectively monitoring the health and performance of the network hardware.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved. The flaw is triggered when the daemon processes specific, valid SNMPv3 queries, leading to a memory leak. An authenticated network-based attacker can exploit this by repeatedly sending these queries to exhaust the process memory. This eventually causes the snmpd process to crash and restart, resulting in a denial-of-service for SNMP-based system monitoring. The issue is resolved in various service releases including 21.2R3-S8, 21.4R3-S7, 22.1R3-S6, and others.

Affected products

  • Juniper Networks Junos OS All versions before 21.2R3-S8; 21.4 before 21.4R3-S7; 22.1 before 22.1R3-S6; 22.2 before 22.2R3-S4; 22.3 before 22.3R3-S3; 22.4 before 22.4R3-S2; 23.2 before 23.2R2; 23.4 before 23.4R2
  • Juniper Networks Junos OS Evolved All versions before 21.2R3-S8-EVO; 21.4 before 21.4R3-S7-EVO; all versions of 22.1-EVO; 22.2 before 22.2R3-S4-EVO; 22.3 before 22.3R3-S3-EVO; all versions of 22.4-EVO; 23.2 before 23.2R2-EVO; 23.4 before 23.4R2-EVO

Timeline

  • 2026-07-09: advisory: Initial publication of JSA110074

References

Related threats