HarborGuard / CVE
Back to search
HIGHCVE-2026-33781Published Modified CNA juniper

CVE-2026-33781: Junos OS: EX Series, QFX Series: In a VXLAN scenario when specific control protocol packets are received, memory leaks and eventually no traffic is passed

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX and QFX Series devices allow an unauthenticated, adjacent attacker to cause a complete Denial of Service (DoS). On EX4k, and QFX5k platforms configured as service-provider edge devices, if L2PT is enabled on the UNI and VSTP is enabled on NNI in VXLAN scenarios, receiving VSTP BPDUs on UNI leads to packet buffer allocation failures, resulting in the device to not pass traffic anymore until it is manually recovered with a restart.This issue affects Junos OS: * 24.4 releases before 24.4R2, * 25.2 releases before 25.2R1-S1, 25.2R2. This issue does not affect Junos OS releases before 24.4R1.

Metrics

CVSS v4.0
7.1
Severity
HIGH
Fixed in
0
Affected Products
1

Fix available

024.4R225.2R1-S1, 25.2R2
Affected packages
  • Juniper Networks / Junos OS
    < 24.4R2 (from 24.4) · < 25.2R1-S1, 25.2R2 (from 25.2)
    Fixed in 0
CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/RE:M
References
CVE-2026-33781: Junos OS: EX Series, QFX Series: In a VXLAN scenario when specific control protocol packets are received, memory leaks and eventually no traffic is passed | HarborGuard CVE