Description
An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS).

When TCP proxy is engaged in a flow session, to support ALGs, Advanced Anti-Malware, ICAP or UTM, a TCP packet with specifically malformed TCP header will cause flow processing daemon (flowd) to crash and restart. This causes a complete service outage until the system has automatically recovered.



This issue affects Junos OS on MX with SPC3, and SRX Series: 



* 23.4 versions before 23.4R2-S7, 
* 24.2 versions before 24.2R2-S4, 
* 24.4 versions before 24.4R2-S3,
* 25.2 versions before 25.2R2.




This issue does not affect releases before 23.4R1.
Published: 2026-07-09
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series. A specially crafted TCP packet with a malformed header bypasses input validation and causes the flow processing daemon (flowd) to crash. The crash forces a daemon restart and results in a temporary complete service outage until the system recovers automatically. The weakness is classified as an input validation vulnerability (CWE‑1284) and does not grant code execution or escalation.

Affected Systems

The vulnerability affects Junos OS on MX Series with SPC3 and SRX Series. All releases before 23.4R2‑S7, 24.2R2‑S4, 24.4R2‑S3, and 25.2R2 are impacted. Versions earlier than 23.4R1 are not vulnerable. Vendor Juniper Networks provides the fix in licensed releases 23.4R2‑S7, 24.2R2‑S4, 24.4R2‑S3, 25.2R2, 25.4R1, and all subsequent releases.

Risk and Exploitability

The vulnerability carries a high CVSS score of 8.7, indicating a severe denial‑of‑service impact. The EPSS score is below 1 %, meaning the likelihood of current exploitation is low, and the issue is not listed in the CISA KEV catalog. A malicious attacker with network access can send the malformed packet to a device where the TCP proxy is enabled for ALGs, Advanced Anti‑Malware, ICAP, or UTM, causing a crash that temporarily disrupts all services. The only protections are the vendor patch or network isolation, as no workaround exists.

Generated by OpenCVE AI on July 29, 2026 at 11:52 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: 23.4R2-S7, 24.2R2-S4, 24.4R2-S3, 25.2R2, 25.4R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade Junos OS to 23.4R2‑S7, 24.2R2‑S4, 24.4R2‑S3, 25.2R2, 25.4R1, or any later release that includes the fix.
  • If the upgrade cannot be performed immediately, isolate the device from external networks that may send malicious packets or disable the TCP proxy for ALGs and related services until a patch is applied.
  • Monitor the flowd process for unexpected restarts and configure alerts to detect recurring DoS events, ensuring prompt remediation if the crash occurs.

Generated by OpenCVE AI on July 29, 2026 at 11:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS). When TCP proxy is engaged in a flow session, to support ALGs, Advanced Anti-Malware, ICAP or UTM, a TCP packet with specifically malformed TCP header will cause flow processing daemon (flowd) to crash and restart. This causes a complete service outage until the system has automatically recovered. This issue affects Junos OS on MX with SPC3, and SRX Series:  * 23.4 versions before 23.4R2-S7,  * 24.2 versions before 24.2R2-S4,  * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R2. This issue does not affect releases before 23.4R1.
Title Junos OS: MX with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd crash
Weaknesses CWE-1284
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M'}


Subscriptions

Juniper Networks Junos Os
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T15:28:45.274Z

Reserved: 2026-06-23T16:27:00.248Z

Link: CVE-2026-57023

cve-icon Vulnrichment

Updated: 2026-07-10T15:28:41.871Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input