8.7

CVE-2026-21913

An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on EX4000 models allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

On EX4000 models with 48 ports (EX4000-48T, EX4000-48P, EX4000-48MP) a high volume of traffic destined to the device will cause an FXPC crash and restart, which leads to a complete service outage until the device has automatically restarted.




The following reboot reason can be seen in the output of 'show chassis routing-engine' and as a log message:

  reason=0x4000002 reason_string=0x4000002:watchdog + panic with core dump 




This issue affects Junos OS on EX4000-48T, EX4000-48P and EX4000-48MP:



  *  24.4 versions before 24.4R2,
  *  25.2 versions before 25.2R1-S2, 25.2R2.




This issue does not affect versions before 24.4R1 as the first Junos OS version for the EX4000 models was 24.4R1.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JuniperJunos Version24.4 Update-
   JuniperEx4000-48mp Version-
   JuniperEx4000-48p Version-
   JuniperEx4000-48t Version-
JuniperJunos Version24.4 Updater1
   JuniperEx4000-48mp Version-
   JuniperEx4000-48p Version-
   JuniperEx4000-48t Version-
JuniperJunos Version24.4 Updater1-s2
   JuniperEx4000-48mp Version-
   JuniperEx4000-48p Version-
   JuniperEx4000-48t Version-
JuniperJunos Version24.4 Updater1-s3
   JuniperEx4000-48mp Version-
   JuniperEx4000-48p Version-
   JuniperEx4000-48t Version-
JuniperJunos Version25.2 Update-
   JuniperEx4000-48mp Version-
   JuniperEx4000-48p Version-
   JuniperEx4000-48t Version-
JuniperJunos Version25.2 Updater1
   JuniperEx4000-48mp Version-
   JuniperEx4000-48p Version-
   JuniperEx4000-48t Version-
JuniperJunos Version25.2 Updater1-s1
   JuniperEx4000-48mp Version-
   JuniperEx4000-48p Version-
   JuniperEx4000-48t Version-
JuniperJunos Version25.2 Updater2
   JuniperEx4000-48mp Version-
   JuniperEx4000-48p Version-
   JuniperEx4000-48t Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.151
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
sirt@juniper.net 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
sirt@juniper.net 8.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X
CWE-665 Improper Initialization

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.