CVE 7.4 HIGH

Junos OS and Junos OS Evolved: An attacker sending a specific genuine BGP packet causes a BGP reset_CVE-2026-33797

7.4 / 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Description

An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS).

An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS:

* 25.2 versions before 25.2R2


This issue doesn't not affected Junos OS versions before 25.2R1.

This issue affects Junos OS Evolved:
* 25.2-EVO versions before 25.2R2-EVO


This issue doesn't not affected Junos OS Evolved versions before 25.2R1-EVO.

eBGP and iBGP are affected.
IPv4 and IPv6 are affected.

Basic Information

ID CVE-2026-33797
Source juniper
Published Apr 9, 2026 at 21:31

Affected Product

Vendor Juniper Networks
Product Junos OS
Version 25.2
Affected Versions Juniper Networks Junos OS 25.2
Juniper Networks Junos OS Evolved 25.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.