Description
An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion, resulting in a process crash and restart, impacting the ability to monitor the system via SNMP.

Memory usage can be monitored using the following command:

user@device> show system processes extensive | match snmpd




This issue affects:

Junos OS:


* all versions before 21.2R3-S8;
* from 21.4 before 21.4R3-S7;
* from 22.1 before 22.1R3-S6;
* from 22.2 before 22.2R3-S4;
* from 22.3 before 22.3R3-S3;
* from 22.4 before 22.4R3-S2;
* from 23.2 before 23.2R2;
* from 23.4 before 23.4R2.



Junos OS Evolved:
* all versions before 21.2R3-S8-EVO;
* from 21.4 before 21.4R3-S7-EVO;
* all versions of 22.1-EVO,
* from 22.2 before 22.2R3-S4-EVO;
* from 22.3 before 22.3R3-S3-EVO;
* all versions of 22.4-EVO,
* from 23.2 before 23.2R2-EVO;
* from 23.4 before 23.4R2-EVO.
Published: 2026-07-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write vulnerability in Juniper Networks’ SNMP daemon (snmpd) allows an authenticated, network‑based attacker to trigger a memory leak by sending particular SNMPv3 queries. Repeated requests gradually exhaust snmpd’s memory, causing the process to crash and restart. The crash disables SNMP monitoring, resulting in a denial of service for management and performance‑monitoring functions.

Affected Systems

Juniper Networks Junos OS and Junos OS Evolved. All releases older than Junos OS 21.2R3‑S8, 21.4R3‑S7, 22.1R3‑S6, 22.2R3‑S4, 22.3R3‑S3, 22.4R3‑S2, 23.2R2 or 23.4R2 are vulnerable. In Junos OS Evolved, all releases before 21.2R3‑S8‑EVO, 21.4R3‑S7‑EVO, 22.2R3‑S4‑EVO, 22.3R3‑S3‑EVO, 23.2R2‑EVO, 23.4R2‑EVO as well as the entire 22.1‑EVO and 22.4‑EVO series are affected.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of <1% reflects a low likelihood of exploitation. The vulnerability requires network access to SNMPv3 with valid authentication and sustained traffic to exhaust memory, making it most realistic against an insider or an attacker who has compromised the management network. Because it is not listed in CISA’s KEV catalog, no known public exploits are cataloged, but the impact remains a denial of service for SNMP management. The path of attack involves sending legitimate SNMPv3 requests repeatedly, which the device treats as authenticated traffic and therefore processes, leading to the resource exhaustion that triggers the crash.

Generated by OpenCVE AI on July 28, 2026 at 08:40 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 21.2R3-S8, 21.4R3-S7, 22.1R3-S6, 22.2R3-S4, 22.3R3-S3, 22.4R3-S2, 23.2R2, 23.4R2, 24.2R1, and all subsequent releases. Junos OS Evolved: 21.2R3-S8-EVO, 21.4R3-S7-EVO, 22.2R3-S4-EVO, 22.3R3-S3-EVO, 23.2R2-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue. To reduce the risk of malicious exploitation, use access lists or firewall filters to limit access to the device via SNMPv3 only from trusted hosts.


OpenCVE Recommended Actions

  • Upgrade Junos OS or Junos OS Evolved to a release that includes the fix, such as 21.2R3‑S8, 21.4R3‑S7, 22.1R3‑S6, 22.2R3‑S4, 22.3R3‑S3, 22.4R3‑S2, 23.2R2, 23.4R2 or any subsequent version.
  • Configure access lists or firewall filters to restrict SNMPv3 traffic to trusted hosts only on UDP port 161, ensuring that only authorized clients can reach the device.
  • Use the command "show system processes extensive | match snmpd" to monitor the snmpd process memory usage and take corrective action if the memory consumption grows abnormal.

Generated by OpenCVE AI on July 28, 2026 at 08:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Juniper Networks junos Os Evolved
Vendors & Products Juniper Networks
Juniper Networks junos Os
Juniper Networks junos Os Evolved

Thu, 09 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion, resulting in a process crash and restart, impacting the ability to monitor the system via SNMP. Memory usage can be monitored using the following command: user@device> show system processes extensive | match snmpd This issue affects: Junos OS: * all versions before 21.2R3-S8; * from 21.4 before 21.4R3-S7; * from 22.1 before 22.1R3-S6; * from 22.2 before 22.2R3-S4; * from 22.3 before 22.3R3-S3; * from 22.4 before 22.4R3-S2; * from 23.2 before 23.2R2; * from 23.4 before 23.4R2. Junos OS Evolved: * all versions before 21.2R3-S8-EVO; * from 21.4 before 21.4R3-S7-EVO; * all versions of 22.1-EVO, * from 22.2 before 22.2R3-S4-EVO; * from 22.3 before 22.3R3-S3-EVO; * all versions of 22.4-EVO, * from 23.2 before 23.2R2-EVO; * from 23.4 before 23.4R2-EVO.
Title Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results in memory leak and eventual snmpd crash
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/AU:Y/R:A/V:C/RE:M/U:Green'}


Subscriptions

Juniper Networks Junos Os Junos Os Evolved
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T13:31:54.447Z

Reserved: 2026-03-23T19:46:13.673Z

Link: CVE-2026-33799

cve-icon Vulnrichment

Updated: 2026-07-10T13:31:46.695Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:45:04Z

Weaknesses