Junglewise Threat Intelligence

CVE-2026-57032: Juniper Networks Junos OS DoS in EX Series packet forwarding engine

CVE-2026-57032 · Severity: medium · CVSS 6.5 · Published 2026-07-09

Vendors: Juniper Networks.

Executive brief

A vulnerability in Juniper Networks Junos OS affects several EX Series network switches. An authorized user with low-level access can cause the device's packet forwarding engine to crash by requesting specific unsupported monitoring data. This results in a complete network service outage until the affected hardware module automatically restarts.

Technical details

An Improper Handling of Undefined Parameters vulnerability (CWE-236) exists in the packet forwarding engine (pfe) of Juniper Networks Junos OS. On EX2300, EX3400, EX4000, EX4100, and EX4400 series devices, an authenticated attacker with low privileges can trigger a crash of the Flexible PIC Concentrator (FPC) by attempting to subscribe to an unsupported telemetry sensor path via gRPC. This crash leads to a complete service outage until the module automatically restarts. The issue is resolved in Junos OS versions 23.2R2-S7, 23.4R2-S8, 24.2R2-S5, 24.4R2, and all subsequent releases.

Affected products

  • Juniper Networks Junos OS All versions before 23.2R2-S7, 23.4 versions before 23.4R2-S8, 24.2 versions before 24.2R2-S5, 24.4 versions before 24.4R2

Timeline

  • 2026-07-09: advisory
  • 2026-07-09: disclosed

References