216.73.217.22

CVE-2026-33788

· Published 09/04/2026 22:16 · Modified 09/04/2026 22:16

Labels: CVE-2026-33788 2026-04-09CVE-2026-33788CWE-306[email protected]

Essential information

Published
09/04/2026 22:16
Modified
09/04/2026 22:16
Author
Creator
CVSS
8.5 HIGH (v3) 8.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device. A local user with low privileges can gain direct access to the installed FPCs as a high privileged user, which can potentially lead to a full compromise of the affected component. This issue affects Junos OS Evolved on PTX10004, PTX10008, PTX100016, with JNP10K-LC1201 or JNP10K-LC1202: * All versions before 21.2R3-S8-EVO, * 21.4-EVO versions before 21.4R3-S7-EVO, * 22.2-EVO versions before 22.2R3-S4-EVO, * 22.3-EVO versions before 22.3R3-S3-EVO, * 22.4-EVO versions before 22.4R3-S2-EVO, * 23.2-EVO versions before 23.2R2-EVO.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
juniper / junose cpe:2.3:a:juniper:junose:-:<21.2R3-S8-EVO>:*:*:*:*:*:*
juniper / junose cpe:2.3:a:juniper:junose:21.4-evo:<21.4R3-S7-EVO>:*:*:*:*:*:*
juniper / junose cpe:2.3:a:juniper:junose:22.2-evo:<22.2R3-S4-EVO>:*:*:*:*:*:*
juniper / junose cpe:2.3:a:juniper:junose:22.3-evo:<22.3R3-S3-EVO>:*:*:*:*:*:*
juniper / junose cpe:2.3:a:juniper:junose:22.4-evo:<22.4R3-S2-EVO>:*:*:*:*:*:*
juniper / junose cpe:2.3:a:juniper:junose:23.2-evo:<23.2R2-EVO>:*:*:*:*:*:*

References