Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

When an affected device initiates a TCP connection to an attacker-controlled system that responds with a specific packet, this causes a PFE crash and restart, which affects all services until the system has automatically recovered.
This issue can happen among others in the following scenarios: ALG, SSL proxy, UTM, RTLOG, AppQoE probing, AAMW, ICAP, URL filtering.

This issue affects Junos OS on MX Series with SPC3, SRX5k Series with SPC3, SRX1600 Series, SRX2300 Series, SRX4000 Series, and vSRX Series:

* all versions before 23.2R2-S4,
* 23.4 versions before 23.4R2-S5,
* 24.2 versions before 24.2R2.
Published: 2026-07-09
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper check for unusual or exceptional conditions in Juniper’s Packet Forwarding Engine (PFE) can cause it to crash when a device, after initiating a TCP connection to a remote host, receives a specially crafted response packet. The crash forces the PFE to restart, temporarily disabling all services on the device until the hardware recovers. Because the flaw can be triggered by an unauthenticated, network‑based attacker without privileged access, the vulnerability results in a denial‑of‑service condition that affects the entire system.

Affected Systems

The vulnerability impacts Juniper Networks’ Junos OS on MX Series with SPC3, SRX5k Series with SPC3, SRX1600, SRX2300, SRX4000, and vSRX Series. All firmware versions prior to 23.2R2‑S4, 23.4R2‑S5, and 24.2R2 are affected. The fixed releases are 22.4R3‑S8, 23.2R2‑S4, 23.4R2‑S5, 24.2R2, 24.4R1, and any subsequent releases.

Risk and Exploitability

The CVSS score of 8.2 reflects a high‑severity flaw, while the EPSS score of <1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by initiating a TCP connection to the device and responding with the precise packet that triggers the crash, a scenario that can occur in various network service contexts such as ALG, SSL proxy, UTM, RTLOG, AppQoE probing, AAMW, ICAP, or URL filtering. The impact is a system‑wide service interruption until the PFE restarts automatically.

Generated by OpenCVE AI on July 29, 2026 at 11:53 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: 22.4R3-S8, 23.2R2-S4, 23.4R2-S5, 24.2R2, 24.4R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade Junos OS to a fixed release such as 22.4R3‑S8, 23.2R2‑S4, 23.4R2‑S5, 24.2R2, or any newer version.
  • If an upgrade is not possible immediately, isolate the device from untrusted networks and block inbound traffic capable of initiating the vulnerable TCP connections.
  • Disable or limit features that trigger the vulnerable PFE path, such as ALG, SSL proxy, UTM, RTLOG, AppQoE probing, AAMW, ICAP, and URL filtering until the patch is applied.

Generated by OpenCVE AI on July 29, 2026 at 11:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affected device initiates a TCP connection to an attacker-controlled system that responds with a specific packet, this causes a PFE crash and restart, which affects all services until the system has automatically recovered. This issue can happen among others in the following scenarios: ALG, SSL proxy, UTM, RTLOG, AppQoE probing, AAMW, ICAP, URL filtering. This issue affects Junos OS on MX Series with SPC3, SRX5k Series with SPC3, SRX1600 Series, SRX2300 Series, SRX4000 Series, and vSRX Series: * all versions before 23.2R2-S4, * 23.4 versions before 23.4R2-S5, * 24.2 versions before 24.2R2.
Title Junos OS: MX Series with SPC3, SRX Series: Specific packet in response to a TCP connection establishment by the affected device can crash the PFE
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/R:A/RE:M'}


Subscriptions

Juniper Networks Junos Os
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:31:13.320Z

Reserved: 2026-06-23T16:27:00.248Z

Link: CVE-2026-57022

cve-icon Vulnrichment

Updated: 2026-07-10T14:31:09.204Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions