Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-33801

Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
09/07/2026
Última modificación:
13/07/2026

Descripción

*** Pendiente de traducción *** An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS).<br /> <br /> Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd crash occurs before the update can be readvertised, so there is no downstream propagation.<br /> <br /> <br /> This issue affects:<br /> <br /> <br /> <br /> * Junos OS versions 25.2 before 25.2R2;<br /> <br /> <br /> * Junos OS Evolved versions 25.2 before 25.2R2-EVO.<br /> <br /> <br /> <br /> <br /> This issue doesn&amp;#39;t affect Junos OS versions before 25.2R1 nor Junos OS Evolved versions before 25.2R1-EVO.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:juniper:junos:25.2:-:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:25.2:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:25.2:r1-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:25.2:r1-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:25.2:-:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:25.2:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:25.2:r1-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos_os_evolved:25.2:r1-s2:*:*:*:*:*:*


Referencias a soluciones, herramientas e información