Junglewise Threat Intelligence

CVE-2026-57024: Juniper Networks Junos OS DoS in IKE daemon iked

CVE-2026-57024 · Severity: medium · CVSS 5.3 · Published 2026-07-09

Vendors: Juniper Networks.

Executive brief

A vulnerability in Juniper Networks Junos OS affects certain MX and SRX series devices used for secure VPN connections. An issue with how the system tracks VPN connections can cause the VPN service to crash repeatedly after many failed connection attempts. This results in a denial-of-service where new VPN tunnels cannot be established and existing ones cannot be maintained, requiring a full system reboot to restore operations.

Technical details

A 'Use of Multiple Resources with Duplicate Identifier' (CWE-694) vulnerability exists in the Internet Key Exchange daemon (iked) of Juniper Networks Junos OS. On affected MX with SPC3 and SRX devices, a large number of failed VPN negotiations eventually triggers a peer index rollover. When this occurs, new peers are assigned index values already in use, causing the iked process to crash repeatedly. This prevents the establishment of new VPN connections and the rekeying of existing ones. The vulnerability is exploitable by an unauthenticated network-based attacker and requires a system reboot for recovery. The issue specifically affects systems running iked rather than the older kmd process.

Affected products

  • Juniper Networks Junos OS All versions before 23.2R2-S7, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S3, 24.4 versions before 24.4R2-S4, 25.2 versions before 25.2R1-S1

Timeline

  • 2026-07-09: advisory: Initial advisory published by Juniper Networks

References