Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-33797

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-20 Validación incorrecta de entrada
Fecha de publicación:
09/04/2026
Última modificación:
09/04/2026

Descripción

*** Pendiente de traducción *** An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS).<br /> <br /> An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS:<br /> <br /> * 25.2 versions before 25.2R2<br /> <br /> <br /> This issue doesn&amp;#39;t not affected Junos OS versions before 25.2R1.<br /> <br /> This issue affects Junos OS Evolved: <br /> * 25.2-EVO versions before 25.2R2-EVO<br /> <br /> <br /> This issue doesn&amp;#39;t not affected Junos OS Evolved versions before 25.2R1-EVO.<br /> <br /> eBGP and iBGP are affected.<br /> IPv4 and IPv6 are affected.

Referencias a soluciones, herramientas e información