CVE-2026-33800 Details
Description
An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD session flaps generate respective up/down events which are queued by PFEMAN for processing. Especially in a Virtual-Chassis (VC) scenario with locality‑bias configured, processing takes a significant amount of time for each event. If these sessions keep flapping, new events are constantly added, and in turn PFEMAN never completes processing these events. This results in the PFEMAN watchdog timer expiring, which causes the FPC to crash and restart, representing a complete service outage. This issue only affects MX series FPCs up to and including MPC9, and LC2101/2103 and LC480. It does not affect MPC10/11, LC4800/9600, and MX304. This issue affects Junos OS on MX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R2.
A vulnerability allowing denial-of-service conditions has been identified in the Packet Forwarding Engine of Juniper Networks Junos OS on MX Series routers. This issue arises from an unchecked input for loop conditions, which allows an unauthenticated, adjacent attacker to cause a service outage. The vulnerability affects all versions prior to 23.2R2-S7, as well as specific 23.4, 24.2, 24.4, and 25.2 versions. In a Virtual-Chassis scenario with locality-bias configured, the vulnerability can be exploited by causing Micro-BFD sessions to flap, generating up/down events that PFEMAN must process. This processing delay can lead to a watchdog timer expiration, causing the FPC to crash and restart, resulting in a complete service outage.
Users can upgrade to Junos OS versions 23.2R2-S7, 23.4R2-S8, 24.2R2-S4, 24.4R2-S3, 25.2R2, 25.4R1, or any subsequent release. As a workaround, BFD can be configured with an increased holddown-timer to allow queued events to be processed before new up events occur.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://supportportal.juniper.net/JSA110075 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-606 | Unchecked Input for Loop Condition | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | < 23.2 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.2 r2-s3 23.2 r2-s4 23.2 r2-s5 23.2 r2-s6 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 23.4 r2-s4 23.4 r2-s5 23.4 r2-s6 23.4 r2-s7 24.2 - 24.2 r1 24.2 r1-s1 24.2 r1-s2 24.2 r2 24.2 r2-s1 24.2 r2-s2 24.2 r2-s3 24.4 - 24.4 r1 24.4 r1-s2 24.4 r1-s3 24.4 r2 24.4 r2-s1 24.4 r2-s2 25.2 - 25.2 r1 25.2 r1-s1 25.2 r1-s2 |
CPE
Remediation
| |
| juniper lc2101 | All versions |
CPE
Remediation
| |
| juniper lc2103 | All versions |
CPE
Remediation
| |
| juniper lc4800 | All versions |
CPE
Remediation
| |
| juniper mpc1 | All versions |
CPE
Remediation
| |
| juniper mpc1 q | All versions |
CPE
Remediation
| |
| juniper mpc1e | All versions |
CPE
Remediation
| |
| juniper mpc1e q | All versions |
CPE
Remediation
| |
| juniper mpc2 | All versions |
CPE
Remediation
| |
| juniper mpc2 eq | All versions |
CPE
Remediation
| |
| juniper mpc2 q | All versions |
CPE
Remediation
| |
| juniper mpc2e | All versions |
CPE
Remediation
| |
| juniper mpc2e eq | All versions |
CPE
Remediation
| |
| juniper mpc2e ng | All versions |
CPE
Remediation
| |
| juniper mpc2e ng q | All versions |
CPE
Remediation
| |
| juniper mpc2e p | All versions |
CPE
Remediation
| |
| juniper mpc2e q | All versions |
CPE
Remediation
| |
| juniper mpc3e | All versions |
CPE
Remediation
| |
| juniper mpc3e-3d-ng | All versions |
CPE
Remediation
| |
| juniper mpc3e-3d-ng-q | All versions |
CPE
Remediation
| |
| juniper mpc6e | All versions |
CPE
Remediation
| |
| juniper mpc7e-10g | All versions |
CPE
Remediation
| |
| juniper mpc7e-mrate | All versions |
CPE
Remediation
| |
| juniper mpc8e | All versions |
CPE
Remediation
| |
| juniper mpc9e | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 26, 2026 | Initial Analysis | [email protected] |
| Jul 20, 2026 | CVE Modified | [email protected] |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |