CVE-2026-0203 Details
Description
An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an unauthenticated, network-adjacent attacker sending a specifically malformed ICMP packet to cause an FPC to crash and restart, resulting in a Denial of Service (DoS). When an ICMP packet is received with a specifically malformed IP header value, the FPC receiving the packet crashes and restarts. Due to the specific type of malformed packet, adjacent upstream routers would not forward the packet, limiting the attack surface to adjacent networks. This issue only affects ICMPv4. ICMPv6 is not vulnerable to this issue. This issue does not affect AFT-based line cards such as the MPC10, MPC11, LC4800, LC9600, and MX304. This issue affects Junos OS: * all versions before 21.2R3-S9, * from 21.4 before 21.4R3-S10, * from 22.2 before 22.2R3-S7, * from 22.3 before 22.3R3-S4, * from 22.4 before 22.4R3-S5, * from 23.2 before 23.2R2-S3, * from 23.4 before 23.4R2-S3, * from 24.2 before 24.2R1-S2, 24.2R2.
A denial-of-service vulnerability has been identified in Juniper Networks Junos OS, all versions prior to 21.2R3-S9, from 21.4 prior to 21.4R3-S10, from 22.2 prior to 22.2R3-S7, from 22.3 prior to 22.3R3-S4, from 22.4 prior to 22.4R3-S5, from 23.2 prior to 23.2R2-S3, from 23.4 prior to 23.4R2-S3, and from 24.2 prior to 24.2R1-S2, 24.2R2. This vulnerability arises from improper handling of exceptional conditions in packet processing, allowing an unauthenticated, network-adjacent attacker to send a specifically malformed ICMPv4 packet that causes a forwarding plane component (FPC) to crash and restart. The malformed packet is not forwarded by adjacent upstream routers, limiting the attack surface to adjacent networks.
Users can upgrade to Junos OS versions 20.2R3-S10, 21.2R3-S9, 21.4R3-S10, 22.2R3-S7, 22.3R3-S4, 22.4R3-S5, 23.2R2-S3, 23.4R2-S3, 24.2R1-S2, 24.2R2, 24.4R1, or any subsequent release. Instructions for downloading these updates are available on the Juniper Networks Customer Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA104294 | [email protected] | Vendor Advisory |
| https://supportportal.juniper.net/JSA104294 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-755 | Improper Handling of Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | < 21.2 21.2 - 21.2 r1 21.2 r1-s1 21.2 r1-s2 21.2 r2 21.2 r2-s1 21.2 r2-s2 21.2 r3 21.2 r3-s1 21.2 r3-s2 21.2 r3-s3 21.2 r3-s4 21.2 r3-s5 21.2 r3-s6 21.2 r3-s7 21.2 r3-s8 21.4 - 21.4 r1 21.4 r1-s1 21.4 r1-s2 21.4 r2 21.4 r2-s1 21.4 r2-s2 21.4 r3 21.4 r3-s1 21.4 r3-s2 21.4 r3-s3 21.4 r3-s4 21.4 r3-s5 21.4 r3-s6 21.4 r3-s7 21.4 r3-s8 21.4 r3-s9 22.2 - 22.2 r1 22.2 r1-s1 22.2 r1-s2 22.2 r2 22.2 r2-s1 22.2 r2-s2 22.2 r3 22.2 r3-s1 22.2 r3-s2 22.2 r3-s3 22.2 r3-s4 22.2 r3-s5 22.2 r3-s6 22.3 - 22.3 r1 22.3 r1-s1 22.3 r1-s2 22.3 r2 22.3 r2-s1 22.3 r2-s2 22.3 r3 22.3 r3-s1 22.3 r3-s2 22.3 r3-s3 22.4 - 22.4 r1 22.4 r1-s1 22.4 r1-s2 22.4 r2 22.4 r2-s1 22.4 r2-s2 22.4 r3 22.4 r3-s1 22.4 r3-s2 22.4 r3-s3 22.4 r3-s4 23.2 - 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 24.2 - 24.2 r1 24.2 r1-s1 24.2 r2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 10, 2026 | CVE Modified | [email protected] |
| Jan 23, 2026 | Initial Analysis | [email protected] |
| Jan 15, 2026 | New CVE Received | [email protected] |