A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS).
On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, local attacker with no specific permissions or class can execute a specific, privileged CLI 'request' command which will cause complete traffic impact until the system automatically recovers.
This issue affects Junos OS on EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400:
* 23.2R2 versions before 23.2R2-S6,
* 23.4 versions before 23.4R2-S8,
* 24.2 versions before 24.2R2-S4,
* 24.4 versions before 24.4R2-S3,
* 25.2 versions before 25.2R2,
* 25.4 versions before 25.4R1-S1.
References
| Link | Resource |
|---|---|
| https://supportportal.juniper.net/JSA110077 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-07-09 22:17
Updated : 2026-07-14 16:59
NVD link : CVE-2026-33802
Mitre link : CVE-2026-33802
CVE.ORG link : CVE-2026-33802
JSON object : View
Products Affected
juniper
- ex4400
- ex4000
- ex2300
- junos
- ex4300-mp
- ex4100
CWE
CWE-862
Missing Authorization
