Description
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS).



On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, local attacker with no specific permissions or class can execute a specific, privileged CLI 'request' command which will cause complete traffic impact until the system automatically recovers.

This issue affects Junos OS on EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400:


* 23.2R2 versions before 23.2R2-S6,
* 23.4 versions before 23.4R2-S8,
* 24.2 versions before 24.2R2-S4,
* 24.4 versions before 24.4R2-S3,
* 25.2 versions before 25.2R2,
* 25.4 versions before 25.4R1-S1.
Published: 2026-07-09
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated user without any specific permissions can execute a privileged CLI 'request' command on Juniper Networks Junos OS for EX Series switches, causing a complete traffic impact until the system automatically recovers. The flaw is a Missing Authorization weakness (CWE‑862) that allows local attackers to trigger a service‑impacting denial‑of‑service condition. The impact is limited to the local device and results in downtime of network traffic handled by the switch.

Affected Systems

The vulnerability affects Juniper Networks Junos OS on EX 2300, EX 4000, EX 4100, EX 4300‑MP (Multigigabit), and EX 4400 switches. Affected releases include all versions of 23.2R2 before 23.2R2‑S6, 23.4 before 23.4R2‑S8, 24.2 before 24.2R2‑S4, 24.4 before 24.4R2‑S3, 25.2 before 25.2R2, and 25.4 before 25.4R1‑S1.

Risk and Exploitability

The CVSS base score is 6.8, categorizing it as a moderate severity issue; the EPSS score indicates a low exploitation probability (<1%). The vulnerability is not listed in the CISA KEV catalog. The vulnerability is exploitable from a local, authenticated context, meaning an attacker must already have user credentials or physical access to the device. Once the command is run, the switch experiences a denial‑of-service that persists until the system reboots or recovers automatically. A workaround is to apply command authorization to limit the 'request' command to privileged users only, but the primary mitigation remains applying any of the patched releases.

Generated by OpenCVE AI on July 29, 2026 at 11:55 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S6, 23.4R2-S8, 24.2R2-S4, 24.4R2-S3, 25.2R2, 25.4R1-S1, 25.4R2, 26.2R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue. To reduce the risk of exploitation use command authorization to limit access to 'request' commands.


OpenCVE Recommended Actions

  • Upgrade the device to any Junos OS release from 23.2R2‑S6, 23.4R2‑S8, 24.2R2‑S4, 24.4R2‑S3, 25.2R2, 25.4R1‑S1, 25.4R2, 26.2R1 or later.
  • If upgrading is not immediately possible, configure command authorization to restrict the 'request' command to privileged users only, thereby preventing unauthorized execution.
  • Enable and monitor CLI audit logs to detect unauthorized actions while remediation is pending.

Generated by OpenCVE AI on July 29, 2026 at 11:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS). On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, local attacker with no specific permissions or class can execute a specific, privileged CLI 'request' command which will cause complete traffic impact until the system automatically recovers. This issue affects Junos OS on EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400: * 23.2R2 versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R2, * 25.4 versions before 25.4R1-S1.
Title Junos OS: EX Series: Unauthorized users can execute service-impacting CLI command
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M'}


Subscriptions

Juniper Networks Junos Os
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T13:28:31.126Z

Reserved: 2026-03-23T19:46:13.673Z

Link: CVE-2026-33802

cve-icon Vulnrichment

Updated: 2026-07-10T13:28:26.409Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses