CVE-2026-57031
Juniper Junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters. On MX Series devices with MPC10/11, LC4800/9600, and MX304 with subscribers configured on static interfaces, ingress firewall filters are not enforced, so that neither protocol level nor upstream bandwidth limitation are in effect. This issue affects Junos OS on MX with MPC10/11, LC4800/9600/4802, and MX304: * 23.2 versions from 23.2R2-S1 before 23.2R2-S7, * 23.4 versions from 23.4R2 before 23.4R2-S7, * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S2, * 25.2 versions before 25.2R2.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable only from the same local or logical network.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 4.7 (v3.1)
- Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N- CVSS v4
- 5.3
- Weakness
- CWE-754
- Assigned by
- sirt@juniper.net
Dates
- Published
- 2026-07-09
- Last modified
- 2026-08-25
- Sources
- NVD
Affected products
- Juniper Junos23.2, 23.4, 24.2, 24.4, 25.2
- Juniper Lc4800all versions
- Juniper Lc4802all versions
- Juniper Lc9600all versions
- Juniper Mpc10e-10call versions
- Juniper Mpc10e-15call versions
- Juniper Mpc11all versions
- Juniper Mx304all versions
As listed in the NVD configuration data. Not a statement about your estate.