Description
A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).



On an MX with SPC3 and SRX devices configured for VPN service, when a large number of VPN negotiations fail a peer index rollover will eventually occur. As a result, new peers are assigned index values that are already in use and the iked process starts to crash repeatedly. This results in failure to establish new VPN connections and rekeying existing ones. To restore service the system must be rebooted.
Please note that the index value can't be monitored, so customers should monitor tunnel up and down events and if a lot of events occur over an extended period of time it becomes likely that this issue occurs.

To be exposed to this issue the system needs to run iked (vs. kmd which is not affected), which can be verified with:

user@host> show system processes extensive | match "KMD|IKED"
This issue affects Junos OS on MX with SPC3, SRX Series:


* all versions before 23.2R2-S7,
* 23.4 versions before 23.4R2-S6,
* 24.2 versions before 24.2R2-S3,
* 24.4 versions before 24.4R2-S4,
* 25.2 versions before 25.2R1-S1.
Published: 2026-07-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows unauthenticated, network-based attackers to trigger a denial‑of‑service. This weakness is a Use of Multiple Resources with Duplicate Identifier vulnerability (CWE‑694). When a large number of VPN negotiations fail, the daemon’s peer index rolls over and new peers are assigned indices that are already in use. This causes iked to crash repeatedly, preventing new VPN connections from being established and interrupting rekeying of existing ones. The crash cannot be detected or monitored directly; the only way to recover is by rebooting the device.

Affected Systems

Juniper Networks Junos OS running on MX with SPC3 and SRX Series devices that execute iked. All releases prior to 23.2R2-S7, 23.4R2-S6, 24.2R2-S3, 24.4R2-S4, and 25.2R1-S1 are affected; subsequent releases contain the fix.

Risk and Exploitability

Based on the description, it is inferred that attackers only need to send a large volume of failed VPN negotiation packets, with no authentication or special privileges required. The CVSS score of 6.9 reflects a moderate severity risk. The EPSS score of <1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation results in permanent loss of VPN availability until the device is rebooted.

Generated by OpenCVE AI on July 28, 2026 at 08:38 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S7, 23.4R2-S6, 24.2R2-S3, 24.4R2-S4, 25.2R1-S1, 25.2R2, 25.4R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade Junos OS to a release that includes the fix, such as 23.2R2-S7, 23.4R2-S6, 24.2R2-S3, 24.4R24, 25.2R1-S1 or newer.
  • Enable monitoring of VPN tunnel up/down events to detect abnormal failure rates and alert operators when a sustained burst of rejections occurs.
  • If a prolonged burst of failures is observed and a patch is not immediately available, reboot the device to restore iked functionality, but pursue a patch as soon as possible.

Generated by OpenCVE AI on July 28, 2026 at 08:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On an MX with SPC3 and SRX devices configured for VPN service, when a large number of VPN negotiations fail a peer index rollover will eventually occur. As a result, new peers are assigned index values that are already in use and the iked process starts to crash repeatedly. This results in failure to establish new VPN connections and rekeying existing ones. To restore service the system must be rebooted. Please note that the index value can't be monitored, so customers should monitor tunnel up and down events and if a lot of events occur over an extended period of time it becomes likely that this issue occurs. To be exposed to this issue the system needs to run iked (vs. kmd which is not affected), which can be verified with: user@host> show system processes extensive | match "KMD|IKED" This issue affects Junos OS on MX with SPC3, SRX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S6, * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R1-S1.
Title Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously
Weaknesses CWE-694
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/AU:Y/R:U/RE:M'}


Subscriptions

Juniper Networks Junos Os
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:31:54.759Z

Reserved: 2026-06-23T16:27:00.248Z

Link: CVE-2026-57024

cve-icon Vulnrichment

Updated: 2026-07-10T14:31:49.085Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:45:04Z

Weaknesses
  • CWE-694

    Use of Multiple Resources with Duplicate Identifier