PT-2026-31747 · Juniper Networks · Ex4100+4
Published
2026-04-09
·
Updated
2026-04-09
·
CVE-2026-33773
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS versions 23.4R2-S6 through 24.2R2-S3
Description
A flaw exists in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series devices. An unauthenticated, network-based attacker can cause an integrity impact to downstream networks. This occurs when the same family inet or inet6 filter is applied on an IRB interface and on a physical interface as an egress filter on EX4100, EX4400, EX4650 and QFX5120 devices, resulting in only one of the two filters being applied, potentially allowing unintended traffic to be sent.
Recommendations
Update to a version later than 24.2R2-S3.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ex4100
Ex4400
Ex4650
Junos
Qfx5120