Description
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion.


Due to an incorrect initialization, a process which should only be able to communicate internally within the device, can be reached over the network via an open port. This leads to unauthorized access to the license management.

This issue affects all Junos OS Evolved versions before 23.2R2-EVO.
Published: 2026-07-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Improper Restriction of Communication in Juniper Networks Junos OS Evolved lets an unauthenticated network attacker reach a process that should be limited to internal communication. By connecting to an unintentionally exposed port, the attacker can access the device’s license management subsystem and trigger license exhaustion, which can degrade or stop services. This weakness aligns with CWE‑923, indicating that an open channel was not adequately constrained.

Affected Systems

The vulnerability is present in all Junos OS Evolved releases earlier than 23.2R2‑EVO. Devices running any firmware version prior to 23.2R2‑EVO are vulnerable until they are upgraded to a supported release.

Risk and Exploitability

The CVSS score of 6.9 reflects moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the bug is not listed in the CISA KEV catalog. The vector is a network‑based, unauthenticated connection to the exposed port; no user interaction or elevated privileges are required. If exploited, the attacker can deplete licensed resources and cause a denial of service.

Generated by OpenCVE AI on July 29, 2026 at 11:51 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 23.2R2-EVO, 23.4R1-EVO, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue. Please ensure that your control plane protection only explicitly permits access to ports intended to be reachable and only from authorized endpoints. All other traffic destined to the control plane should be disallowed.


OpenCVE Recommended Actions

  • Update Junos OS Evolved to release 23.2R2‑EVO or any subsequent version such as 23.4R1‑EVO.
  • Configure control‑plane protection so that only endpoints, blocking all other inbound traffic.
  • Enable logging and alerts for any connection attempts on the exposed port to detect potential exploitation attempts.

Generated by OpenCVE AI on July 29, 2026 at 11:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os Evolved
Vendors & Products Juniper Networks
Juniper Networks junos Os Evolved

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. Due to an incorrect initialization, a process which should only be able to communicate internally within the device, can be reached over the network via an open port. This leads to unauthorized access to the license management. This issue affects all Junos OS Evolved versions before 23.2R2-EVO.
Title Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker
Weaknesses CWE-923
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/AU:Y/R:U/RE:M'}


Subscriptions

Juniper Networks Junos Os Evolved
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:37:21.433Z

Reserved: 2026-06-23T16:27:00.248Z

Link: CVE-2026-57028

cve-icon Vulnrichment

Updated: 2026-07-10T14:37:16.449Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-923

    Improper Restriction of Communication Channel to Intended Endpoints