Description
An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD session flaps generate respective up/down events which are queued by PFEMAN for processing. Especially in a Virtual-Chassis (VC) scenario with locality‑bias configured, processing takes a significant amount of time for each event. If these sessions keep flapping, new events are constantly added, and in turn PFEMAN never completes processing these events. This results in the PFEMAN watchdog timer expiring, which causes the FPC to crash and restart, representing a complete service outage.


This issue only affects MX series FPCs up to and including MPC9, and LC2101/2103 and LC480. It does not affect MPC10/11, LC4800/9600, and MX304.

This issue affects Junos OS on MX Series:


* all versions before 23.2R2-S7,
* 23.4 versions before 23.4R2-S8,
* 24.2 versions before 24.2R2-S4,
* 24.4 versions before 24.4R2-S3,
* 25.2 versions before 25.2R2.
Published: 2026-07-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unchecked input for loop condition in the Packet Forwarding Engine of Juniper Junos OS on MX Series allows an adjacent attacker to trigger a denial‑of‑service attack by causing the PFEMAN to process an unbounded queue of micro‑BFD events. The flaw arises when micro‑BFD sessions flap at a high rate; each up/down event is queued, and with locality‑bias enabled the processing time per event is significant. As new events keep arriving, PFEMAN is unable to finish, its watchdog timer expires, and the FPC crashes. The crash forces a FPC restart, resulting in a complete service outage for the affected router. CWE‑606, unchecked input for loop condition, describes the weakness underlying this fault.

Affected Systems

Juniper Networks Junos OS on MX Series routers. Affected hardware includes all MX Series Field Processing Engines (FPCs) up through MPC9 as well as the LC2101, LC2103 and LC480 chips. The flaw does not impact MPC10 or MPC11, LC4800 or LC4800/9600 series boards, and MX304. Software versions before 23.2R2‑S7, before 23.4R2‑S8, before 24.2R2‑S4, before 24.4R2‑S3 and before 25.2R2 are vulnerable.

Risk and Exploitability

The CVSS score of 7.1 places this issue in the high‑severity range, while the EPSS of <1 % indicates that exploitation probability remains very low at present. The vulnerability is not listed in CISA’s KEV catalog. network segment as the target and can exploit the flaw by generating a high rate of micro‑BFD session flaps; no authentication is required. The attack path is purely through the BFD control plane, and the flaw manifests as a denial‑of‑service via an FPC crash, affecting overall system availability.

Generated by OpenCVE AI on July 28, 2026 at 08:40 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S7, 23.4R2-S8, 24.2R2-S4, 24.4R2-S3, 25.2R2, 25.4R1, and all subsequent releases.


Vendor Workaround

To reduce the risk of exploitation, configure BFD with an increased holddown-timer, so that the queued events can be processed before a new up event occurs: [ ... bfd-liveness-detection holddown-interval milliseconds <value> ]


OpenCVE Recommended Actions

  • Upgrade Junos OS to one of the fixed releases such as 23.2R2‑S7 or newer versions including 25.4R1 and later.
  • If an upgrade cannot be performedddown interval using the bfd‑liveness‑detection holddown‑interval command to reduce the backlog of queued events.
  • Monitor BFD traffic for abnormal flapping and watch for FPC restarts; if instability persists, consider additional tuning or hardware resets.

Generated by OpenCVE AI on July 28, 2026 at 08:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD session flaps generate respective up/down events which are queued by PFEMAN for processing. Especially in a Virtual-Chassis (VC) scenario with locality‑bias configured, processing takes a significant amount of time for each event. If these sessions keep flapping, new events are constantly added, and in turn PFEMAN never completes processing these events. This results in the PFEMAN watchdog timer expiring, which causes the FPC to crash and restart, representing a complete service outage. This issue only affects MX series FPCs up to and including MPC9. It does not affect MPC10/11, LC4800/9600 and MX304. This issue affects Junos OS on MX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R2. An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD session flaps generate respective up/down events which are queued by PFEMAN for processing. Especially in a Virtual-Chassis (VC) scenario with locality‑bias configured, processing takes a significant amount of time for each event. If these sessions keep flapping, new events are constantly added, and in turn PFEMAN never completes processing these events. This results in the PFEMAN watchdog timer expiring, which causes the FPC to crash and restart, representing a complete service outage. This issue only affects MX series FPCs up to and including MPC9, and LC2101/2103 and LC480. It does not affect MPC10/11, LC4800/9600, and MX304. This issue affects Junos OS on MX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R2.

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD session flaps generate respective up/down events which are queued by PFEMAN for processing. Especially in a Virtual-Chassis (VC) scenario with locality‑bias configured, processing takes a significant amount of time for each event. If these sessions keep flapping, new events are constantly added, and in turn PFEMAN never completes processing these events. This results in the PFEMAN watchdog timer expiring, which causes the FPC to crash and restart, representing a complete service outage. This issue only affects MX series FPCs up to and including MPC9. It does not affect MPC10/11, LC4800/9600 and MX304. This issue affects Junos OS on MX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R2.
Title Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps will cause an FPC crash
Weaknesses CWE-606
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M'}


Subscriptions

Juniper Networks Junos Os
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-20T13:05:07.325Z

Reserved: 2026-03-23T19:46:13.673Z

Link: CVE-2026-33800

cve-icon Vulnrichment

Updated: 2026-07-10T13:31:23.582Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:45:04Z

Weaknesses
  • CWE-606

    Unchecked Input for Loop Condition