Description
An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is enabled on an affected device, the processing of a malformed SIP invite packet will cause a flow processing daemon (flowd) crash and restart. This leads to a complete service outage until the system has automatically recovered.



This issue affects Junos OS on MX Series with SPC3 and SRX Series:


* all versions before 23.2R2-S7,
* 23.4 versions before 23.4R2-S8,
* 24.2 versions before 24.2R2-S5,
* 24.4 versions before 24.4R2-S4,
* 25.2 versions before 25.2R2,
* 25.4 versions before 25.4R1-S2.
Published: 2026-07-09
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Juniper Networks Junos OS on MX Series with SPC3 and SRX Series suffers from improper validation of SIP invite syntax (CWE‑1286). When the SIP Application Layer Gateway (ALG) processes a specifically crafted malformed invite packet, the flowd daemon crashes and restarts, stopping packet processing until the system recovers automatically. The crash causes a temporary but complete service outage, affecting all traffic handled by the device during the reboot period.

Affected Systems

Affected systems are Juniper Networks Junos OS running on MX Series with SPC3 and SRX Series. Vulnerable releases include all versions prior to 23.2R2‑S7, all 23.4 releases before 23.4R2‑S8, all 24.2 releases before 24.2R2‑S5, all 24.4 releases before 24.4R2‑S4, all 25.2 releases before 25.2R2, and all 25.4 releases before 25.4R1‑S2.

Risk and Exploitability

The CVSS score of 8.7 classifies the flaw as high severity, while the EPSS score of <1% indicates a low but nonzero chance of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker with network access to the SIP ports (typically 5060/5061) can send a single malformed SIP invite, triggering the flowd crash without requiring authentication or elevated privileges. The impact is a short‑lived denial of service until the device automatically restarts.

Generated by OpenCVE AI on August 1, 2026 at 13:49 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S7, 23.4R2-S8, 24.2R2-S5, 24.4R2-S4, 25.2R2, 25.4R1-S2, 25.4R2, 26.2R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue. To reduce the risk of exploitation customers not requiring the SIP ALG functionality could explicitly disable it (in case it's by default enabled) by configuring: [ security alg sip disable ]


OpenCVE Recommended Actions

  • Upgrade Junos OS to the latest patched release, such as 23.2R2‑S7, 23.4R2‑S8, 24.2R2‑S5, 24.4R2‑S4, 25.2R2, 25.4R1‑S2, or any subsequent release.
  • If the device does not require SIP ALG functionality, disable it by applying the configuration command "[ security alg sip disable ]" to remove the vulnerable processing path.
  • Restrict traffic to the SIP interface using firewalls or access‑control lists so that only trusted networks can send SIP packets, thereby limiting the attack surface.

Generated by OpenCVE AI on August 1, 2026 at 13:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is enabled on an affected device, the processing of a malformed SIP invite packet will cause a flow processing daemon (flowd) crash and restart. This leads to a complete service outage until the system has automatically recovered. This issue affects Junos OS on MX Series with SPC3 and SRX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S5, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R2, * 25.4 versions before 25.4R1-S2.
Title Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash
Weaknesses CWE-1286
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M'}


cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:33:07.076Z

Reserved: 2026-06-23T16:27:00.248Z

Link: CVE-2026-57026

cve-icon Vulnrichment

Updated: 2026-07-10T14:33:03.249Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-09T22:17:07.923

Modified: 2026-07-14T15:03:23.637

Link: CVE-2026-57026

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T14:00:06Z

Weaknesses
  • CWE-1286

    Improper Validation of Syntactic Correctness of Input