Description
An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low privileges to cause a Denial-of-Service (DoS).

If an attempt is made to subscribe to an unsupported telemetry sensor path on EX2300, EX3400, EX4000, EX4100 and EX4400 via gRPC, this causes the FPC to crash. This leads to a complete service outage until the module has automatically restarted. 

The following log message can be seen when this issue happens:

agentd[<PID>]: AGENTD_RESOURCE_NOT_FOUND: No resource name found for <sensor>


This issue affects Junos OS on

EX2300, EX3400, EX4000, EX4100 and EX4400

devices:


* all versions before 23.2R2-S7,
* 23.4 versions before 23.4R2-S8,
* 24.2 versions before 24.2R2-S5,
* 24.4 versions before 24.4R2.
Published: 2026-07-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication-based vulnerability in Juniper Networks Junos OS on EX Series switches allows a low-privilege user to cause a denial-of-service by subscribing to an unsupported telemetry sensor path with gRPC. The packet forwarding engine crashes, stopping the FXPC process and rendering the device unusable until the module restarts. The crash is triggered by an improper handling of undefined parameters and results in a complete service outage. The weakness is categorized as CWE-236, reflecting uncontrolled resource consumption leading to a crash.

Affected Systems

The vulnerability affects Juniper Networks Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 devices. All software versions before 23.2R2-S7, all 23.4 releases before 23.4R2-S8, all 24.2 releases before 24.2R2-S5, and all 24.4 releases before 24.4R2 are impacted.

Risk and Exploitability

The CVSS score is 7.1, indicating a high severity of denial of service. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attack requires authenticated access to the device via gRPC, implying that a threat actor must first gain low-privilege credentials or compromise an existing management session. Once authenticated, the attacker can send an unsupported sensor path request, crash the FXPC process, and disrupt traffic until the module recycles.

Generated by OpenCVE AI on July 29, 2026 at 11:49 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S7, 23.4R2-S8, 24.2R2-S5, 24.4R2, 25.2R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue. To reduce the risk of exploitation use access lists or firewall filters to limit access to the device only from trusted hosts and administrators.


OpenCVE Recommended Actions

  • Upgrade Junos OS to one of the fixed releases 23.2R2-S7, 23.4R2-S8, 24.2R2-S5, 24.4R2, 25.2R1 or newer.
  • Restrict device access through access lists or firewall filters to allow connections only from trusted administrators and hosts.
  • Review and remove any unsupported telemetry sensor path subscriptions from the device configuration to prevent accidental triggering of the crash.

Generated by OpenCVE AI on July 29, 2026 at 11:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low privileges to cause a Denial-of-Service (DoS). If an attempt is made to subscribe to an unsupported telemetry sensor path on EX2300, EX3400, EX4000, EX4100 and EX4400 via gRPC, this causes the FPC to crash. This leads to a complete service outage until the module has automatically restarted.  The following log message can be seen when this issue happens: agentd[<PID>]: AGENTD_RESOURCE_NOT_FOUND: No resource name found for <sensor> This issue affects Junos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 devices: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S5, * 24.4 versions before 24.4R2.
Title Junos OS: EX Series: Subscribing to an unsupported telemetry sensor path causes fxpc process crash
Weaknesses CWE-236
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M'}


Subscriptions

Juniper Networks Junos Os
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:34:50.488Z

Reserved: 2026-06-23T16:27:00.249Z

Link: CVE-2026-57032

cve-icon Vulnrichment

Updated: 2026-07-10T14:34:45.464Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-236

    Improper Handling of Undefined Parameters