PT-2026-31753 · Juniper Networks · Junos Evolved+2
Published
2026-04-09
·
Updated
2026-04-10
·
CVE-2026-33788
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS Evolved on PTX Series versions prior to 21.2R3-S8-EVO, versions 21.4-EVO prior to 21.4R3-S7-EVO, versions 22.2-EVO prior to 22.2R3-S4-EVO, versions 22.3-EVO prior to 22.3R3-S3-EVO, versions 22.4-EVO prior to 22.4R3-S2-EVO, and versions 23.2-EVO prior to 23.2R2-EVO.
Description
A Missing Authentication for Critical Function vulnerability exists in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series. A local attacker with low privileges can gain direct access to FPCs installed in the device. This access allows the attacker to operate as a high-privileged user on the FPCs, potentially leading to a full compromise of the affected component.
Recommendations
Update to a version after 21.2R3-S8-EVO.
Update to a version after 21.4R3-S7-EVO.
Update to a version after 22.2R3-S4-EVO.
Update to a version after 22.3R3-S3-EVO.
Update to a version after 22.4R3-S2-EVO.
Update to a version after 23.2R2-EVO.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flexible Pic Concentrators
Junos Evolved
Ptx Series