216.73.216.233

CVE-2026-21913

· Published 15/01/2026 21:16 · Modified 16/01/2026 15:55

Labels: CVE-2026-21913 2026-01-15CVE-2026-21913[email protected]

Essential information

Published
15/01/2026 21:16
Modified
16/01/2026 15:55
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on EX4000 models allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On EX4000 models with 48 ports (EX4000-48T, EX4000-48P, EX4000-48MP) a high volume of traffic destined to the device will cause an FXPC crash and restart, which leads to a complete service outage until the device has automatically restarted. The following reboot reason can be seen in the output of 'show chassis routing-engine' and as a log message:   reason=0x4000002 reason_string=0x4000002:watchdog + panic with core dump This issue affects Junos OS on EX4000-48T, EX4000-48P and EX4000-48MP: * 24.4 versions before 24.4R2, * 25.2 versions before 25.2R1-S2, 25.2R2. This issue does not affect versions before 24.4R1 as the first Junos OS version for the EX4000 models was 24.4R1.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
juniper / junose cpe:2.3:a:juniper:junose:*:*:*:*:*:*:ex4000-48t:*
juniper / junose cpe:2.3:a:juniper:junose:*:*:*:*:*:*:ex4000-48p:*
juniper / junose cpe:2.3:a:juniper:junose:*:*:*:*:*:*:ex4000-48mp:*
juniper / junose cpe:2.3:a:juniper:junose:<24.4R2:*:*:*:*:*:*:*
juniper / junose cpe:2.3:a:juniper:junose:<25.2R1-S2:*:*:*:*:*:*:*
juniper / junose cpe:2.3:a:juniper:junose:<25.2R2:*:*:*:*:*:*:*

References