CVE-2026-33778 Details
Description
An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complete Denial-of-Service (DoS). If an affected device receives a specifically malformed first ISAKMP packet from the initiator, the kmd/iked process will crash and restart, which momentarily prevents new security associations (SAs) for from being established. Repeated exploitation of this vulnerability causes a complete inability to establish new VPN connections. This issue affects Junos OS on SRX Series and MX Series: * all versions before 22.4R3-S9, * 23.2 version before 23.2R2-S6, * 23.4 version before 23.4R2-S7, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R1-S2, 25.2R2.
A denial-of-service vulnerability has been identified in the IPsec library used by the kmd and iked processes of Juniper Networks Junos OS, specifically on SRX Series and MX Series devices. This vulnerability allows an unauthenticated, network-based attacker to cause the kmd/iked process to crash and restart by sending a malformed first ISAKMP packet. The crash temporarily disrupts the establishment of new security associations (SAs), and repeated exploitation leads to a complete failure in establishing new VPN connections. This issue affects all Junos OS versions prior to 22.4R3-S9, as well as specific versions in the 23.x and 24.x series.
Users can upgrade to Junos OS versions 22.4R3-S9, 23.2R2-S6, 23.4R2-S7, 24.2R2-S4, 24.4R2-S3, 25.2R1-S2, 25.2R2, 25.4R1, or any subsequent release. For more information, refer to Juniper's vulnerability tracking PR1909025.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA107868 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1286 | Improper Validation of Syntactic Correctness of Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | < 22.4 22.4 - 22.4 r1 22.4 r1-s1 22.4 r1-s2 22.4 r2 22.4 r2-s1 22.4 r2-s2 22.4 r3 22.4 r3-s1 22.4 r3-s2 22.4 r3-s3 22.4 r3-s4 22.4 r3-s5 22.4 r3-s6 22.4 r3-s7 22.4 r3-s8 23.2 - 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.2 r2-s3 23.2 r2-s4 23.2 r2-s5 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 23.4 r2-s4 23.4 r2-s5 23.4 r2-s6 24.2 - 24.2 r1 24.2 r1-s1 24.2 r1-s2 24.2 r2 24.2 r2-s1 24.2 r2-s2 24.2 r2-s3 24.4 - 24.4 r1 24.4 r1-s2 24.4 r1-s3 24.4 r2 24.4 r2-s1 24.4 r2-s2 25.2 - 25.2 r1 25.2 r1-s1 25.2 r2 |
CPE
Remediation
| |
| juniper mx10004 | All versions |
CPE
Remediation
| |
| juniper mx10008 | All versions |
CPE
Remediation
| |
| juniper mx2008 | All versions |
CPE
Remediation
| |
| juniper mx2010 | All versions |
CPE
Remediation
| |
| juniper mx2020 | All versions |
CPE
Remediation
| |
| juniper mx204 | All versions |
CPE
Remediation
| |
| juniper mx240 | All versions |
CPE
Remediation
| |
| juniper mx301 | All versions |
CPE
Remediation
| |
| juniper mx304 | All versions |
CPE
Remediation
| |
| juniper mx480 | All versions |
CPE
Remediation
| |
| juniper mx960 | All versions |
CPE
Remediation
| |
| juniper srx1500 | All versions |
CPE
Remediation
| |
| juniper srx1600 | All versions |
CPE
Remediation
| |
| juniper srx2300 | All versions |
CPE
Remediation
| |
| juniper srx300 | All versions |
CPE
Remediation
| |
| juniper srx320 | All versions |
CPE
Remediation
| |
| juniper srx340 | All versions |
CPE
Remediation
| |
| juniper srx345 | All versions |
CPE
Remediation
| |
| juniper srx380 | All versions |
CPE
Remediation
| |
| juniper srx4100 | All versions |
CPE
Remediation
| |
| juniper srx4120 | All versions |
CPE
Remediation
| |
| juniper srx4200 | All versions |
CPE
Remediation
| |
| juniper srx4300 | All versions |
CPE
Remediation
| |
| juniper srx4600 | All versions |
CPE
Remediation
| |
| juniper srx4700 | All versions |
CPE
Remediation
| |
| juniper srx5400 | All versions |
CPE
Remediation
| |
| juniper srx5600 | All versions |
CPE
Remediation
| |
| juniper srx5800 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 17, 2026 | Initial Analysis | [email protected] |
| Apr 9, 2026 | New CVE Received | [email protected] |