CVE-2026-33803 Details
Description
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due to a wrong initialization, a process which should only be able to communicate internally within the device can be reached over the network via an open port. This leads to a device being inadvertently exposed and increased CPU cycles spent processing ingress packets. This issue affects Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24.4R2-S4-EVO, * 25.2 versions before 25.2R2-S1-EVO, * 25.4 versions before 25.4R1-S2-EVO.
A vulnerability in Juniper Networks Junos OS Evolved exists due to improper initialization, allowing an unauthenticated, network-based attacker to access a process intended for internal communication only. This process can be reached over the network via an open port, inadvertently exposing the device and causing increased CPU usage from processing incoming packets. The vulnerability leads to limited information disclosure and availability impact on the device. Affected versions include all prior to 23.2R2-S7-EVO, 23.4 versions before 23.4R2-S8-EVO, 24.2 versions before 24.2R2-S5-EVO, 24.4 versions before 24.4R2-S4-EVO, 25.2 versions before 25.2R2-S1-EVO, and 25.4 versions before 25.4R1-S2-EVO.
Users can upgrade to Junos OS Evolved versions 23.2R2-S7-EVO, 23.4R2-S8-EVO, 24.2R2-S5-EVO, 24.4R2-S4-EVO, 25.2R2-S1-EVO, 25.4R1-S2-EVO, 25.4R2-EVO, 26.2R1-EVO, or any subsequent release. For guidance on which releases vulnerabilities are fixed, refer to Juniper's Knowledge Base article KB16765.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://supportportal.juniper.net/JSA110078 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-923 | Improper Restriction of Communication Channel to Intended Endpoints | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos os evolved | < 23.2 23.2 - 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.2 r2-s3 23.2 r2-s4 23.2 r2-s5 23.2 r2-s6 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 23.4 r2-s4 23.4 r2-s5 23.4 r2-s6 23.4 r2-s7 24.2 - 24.2 r1 24.2 r1-s2 24.2 r2 24.2 r2-s1 24.2 r2-s2 24.2 r2-s3 24.2 r2-s4 24.4 - 24.4 r1 24.4 r1-s2 24.4 r1-s3 24.4 r2 24.4 r2-s1 24.4 r2-s2 24.4 r2-s3 25.2 - 25.2 r1 25.2 r1-s1 25.2 r1-s2 25.2 r2 25.4 - 25.4 r1 25.4 r1-s1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | Initial Analysis | [email protected] |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |