CVE-2026-33779 Details
Description
An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get access to confidential information and potentially modify it. When an SRX device is provisioned to connect to Security Director (SD) cloud, it doesn't perform sufficient verification of the received server certificate. This allows a PITM to intercept the communication between the SRX and SD cloud and access credentials and other sensitive information. This issue affects Junos OS: * all versions before 22.4R3-S9, * 23.2 versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S2, * 25.2 versions before 25.2R1-S2, 25.2R2.
A vulnerability exists in the J-Web interface of Juniper Networks Junos OS on SRX Series devices, due to improper verification of server certificates. This flaw allows a man-in-the-middle (PITM) attacker to intercept communications between the SRX device and the Security Director (SD) cloud, potentially accessing and modifying confidential information such as credentials. The vulnerability affects all Junos OS versions prior to 22.4R3-S9, as well as specific 23.2, 23.4, 24.2, 24.4, and 25.2 versions.
Users can upgrade to Junos OS versions 22.4R3-S9, 23.2R2-S6, 23.4R2-S7, 24.2R2-S3, 24.4R2-S2, 25.2R1-S2, 25.2R2, 25.4R1, or any subsequent release. For guidance on which releases vulnerabilities are fixed, refer to Juniper's KB16765.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA107823 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-296 | Improper Following of a Certificate's Chain of Trust | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | < 22.4 22.4 - 22.4 r1 22.4 r1-s1 22.4 r1-s2 22.4 r2 22.4 r2-s1 22.4 r2-s2 22.4 r3 22.4 r3-s1 22.4 r3-s2 22.4 r3-s3 22.4 r3-s4 22.4 r3-s5 22.4 r3-s6 22.4 r3-s7 22.4 r3-s8 23.2 - 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.2 r2-s3 23.2 r2-s4 23.2 r2-s5 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 23.4 r2-s4 23.4 r2-s5 23.4 r2-s6 24.2 - 24.2 r1 24.2 r1-s1 24.2 r1-s2 24.2 r2 24.2 r2-s1 24.2 r2-s2 24.4 - 24.4 r1 24.4 r1-s2 24.4 r1-s3 24.4 r2 24.4 r2-s1 25.2 - 25.2 r1 25.2 r1-s1 25.2 r2 |
CPE
Remediation
| |
| juniper srx1500 | All versions |
CPE
Remediation
| |
| juniper srx1600 | All versions |
CPE
Remediation
| |
| juniper srx2300 | All versions |
CPE
Remediation
| |
| juniper srx300 | All versions |
CPE
Remediation
| |
| juniper srx320 | All versions |
CPE
Remediation
| |
| juniper srx340 | All versions |
CPE
Remediation
| |
| juniper srx345 | All versions |
CPE
Remediation
| |
| juniper srx380 | All versions |
CPE
Remediation
| |
| juniper srx4100 | All versions |
CPE
Remediation
| |
| juniper srx4120 | All versions |
CPE
Remediation
| |
| juniper srx4200 | All versions |
CPE
Remediation
| |
| juniper srx4300 | All versions |
CPE
Remediation
| |
| juniper srx4600 | All versions |
CPE
Remediation
| |
| juniper srx4700 | All versions |
CPE
Remediation
| |
| juniper srx5400 | All versions |
CPE
Remediation
| |
| juniper srx5600 | All versions |
CPE
Remediation
| |
| juniper srx5800 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 17, 2026 | Initial Analysis | [email protected] |
| Apr 9, 2026 | New CVE Received | [email protected] |