7.4

CVE-2026-33797

Junos OS and Junos OS Evolved: An attacker sending a specific genuine BGP packet causes a BGP reset

An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS).

An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS:

  *  25.2 versions before 25.2R2


This issue does not affect Junos OS versions before 25.2R1.

This issue affects Junos OS Evolved: 
  *  25.2-EVO versions before 25.2R2-EVO


This issue does not affect Junos OS Evolved versions before 25.2R1-EVO.

eBGP and iBGP are affected.
IPv4 and IPv6 are affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JuniperJunos Version25.2 Update-
JuniperJunos Version25.2 Updater1
JuniperJunos Version25.2 Updater1-s1
JuniperJunos Version25.2 Updater1-s2
JuniperJunos Os Evolved Version25.2 Update-
JuniperJunos Os Evolved Version25.2 Updater1
JuniperJunos Os Evolved Version25.2 Updater1-s1
JuniperJunos Os Evolved Version25.2 Updater1-s2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.171
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
sirt@juniper.net 7.1 0 0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:C/RE:M/U:Green
sirt@juniper.net 7.4 2.8 4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.