6.5Medium

Juniper Junos

CVE-2026-33800

An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD session flaps generate respective up/down events which are queued by PFEMAN for processing. Especially in a Virtual-Chassis (VC) scenario with locality‑bias configured, processing takes a significant amount of time for each event. If these sessions keep flapping, new events are constantly added, and in turn PFEMAN never completes processing these events. This results in the PFEMAN watchdog timer expiring, which causes the FPC to crash and restart, representing a complete service outage. This issue only affects MX series FPCs up to and including MPC9, and LC2101/2103 and LC480. It does not affect MPC10/11, LC4800/9600, and MX304. This issue affects Junos OS on MX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R2.

What this means for your business

  • It affects Juniper Junos. It matters if your company, or a supplier that handles your data, runs it.
  • An attacker can use it from inside the same network, without a login, and without anyone at your company clicking anything.
  • FIRST's prediction model gives it a 0.3% chance of attack attempts being seen in the next 30 days, ranking above 19% of all known flaws.

What to do

  1. 1Check whether your company or your suppliers run Juniper Junos, and which version. The affected versions are listed further down this page.
  2. 2If you do, apply the vendor's fix. A patch or vendor advisory has been published.

Not sure if your company is exposed?

Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.

Scoring

CVSS
6.5 (v3.1)
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4
7.1
Weakness
CWE-606
Assigned by
sirt@juniper.net

Dates

Published
2026-07-09
Last modified
2026-08-26
Sources
NVD

Affected products

  • Juniper Junos- 23.2, 23.2, 23.4, 24.2, 24.4, 25.2
  • Juniper Lc2101all versions
  • Juniper Lc2103all versions
  • Juniper Lc4800all versions
  • Juniper Mpc1all versions
  • Juniper Mpc1 Qall versions
  • Juniper Mpc1eall versions
  • Juniper Mpc1e Qall versions
  • Juniper Mpc2all versions
  • Juniper Mpc2 Eqall versions
  • Juniper Mpc2 Qall versions
  • Juniper Mpc2eall versions

As listed in the NVD configuration data. Not a statement about your estate.

References