CVE-2026-21905
Description
A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-SPC3 or MS-MPC allows an unauthenticated network-based attacker sending specific SIP messages over TCP to crash the flow management process, leading to a Denial of Service (DoS). On SRX Series, and MX Series with MX-SPC3 or MS-MPC service cards, receipt of multiple SIP messages causes the SIP headers to be parsed incorrectly, eventually causing a continuous loop and leading to a watchdog timer expiration, crashing the flowd process on SRX Series and MX Series with MX-SPC3, or mspmand process on MX Series with MS-MPC. This issue only occurs over TCP. SIP messages sent over UDP cannot trigger this issue. This issue affects Junos OS on SRX Series and MX Series with MX-SPC3 and MS-MPC: * all versions before 21.2R3-S10, * from 21.4 before 21.4R3-S12, * from 22.4 before 22.4R3-S8, * from 23.2 before 23.2R2-S5, * from 23.4 before 23.4R2-S6, * from 24.2 before 24.2R2-S3, * from 24.4 before 24.4R2-S1, * from 25.2 before 25.2R1-S1, 25.2R2.
CVSS Details
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:C/RE:M/U:Amber Threat Intelligence
Weaknesses 1
Affected Products 113
| Vendor | Product | Version | Range |
|---|---|---|---|
| juniper | junos | * | <21.2 |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.2 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 21.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 22.4 | any |
| juniper | junos | 23.2 | any |
| juniper | junos | 23.2 | any |
| juniper | junos | 23.2 | any |
| juniper | junos | 23.2 | any |
| juniper | junos | 23.2 | any |
| juniper | junos | 23.2 | any |
| juniper | junos | 23.2 | any |
| juniper | junos | 23.2 | any |
| juniper | junos | 23.2 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 24.2 | any |
| juniper | junos | 24.2 | any |
| juniper | junos | 24.2 | any |
| juniper | junos | 24.2 | any |
| juniper | junos | 24.2 | any |
| juniper | junos | 24.2 | any |
| juniper | junos | 24.2 | any |
| juniper | junos | 24.4 | any |
| juniper | junos | 24.4 | any |
| juniper | junos | 24.4 | any |
| juniper | junos | 24.4 | any |
| juniper | junos | 24.4 | any |
| juniper | junos | 25.2 | any |
| juniper | junos | 25.2 | any |
| juniper | junos | 25.2 | any |
| juniper | mx10004 | * | any |
| juniper | mx10008 | * | any |
| juniper | mx2008 | * | any |
| juniper | mx2010 | * | any |
| juniper | mx2020 | * | any |
| juniper | mx204 | * | any |
| juniper | mx240 | * | any |
| juniper | mx304 | * | any |
| juniper | mx480 | * | any |
| juniper | mx960 | * | any |
| juniper | srx1500 | * | any |
| juniper | srx1600 | * | any |
| juniper | srx2300 | * | any |
| juniper | srx300 | * | any |
| juniper | srx320 | * | any |
| juniper | srx340 | * | any |
| juniper | srx345 | * | any |
| juniper | srx380 | * | any |
| juniper | srx4100 | * | any |
| juniper | srx4120 | * | any |
| juniper | srx4200 | * | any |
| juniper | srx4300 | * | any |
| juniper | srx4600 | * | any |
| juniper | srx4700 | * | any |
| juniper | srx5400 | * | any |
| juniper | srx5600 | * | any |
| juniper | srx5800 | * | any |
References 2
- kb.juniper.net https://kb.juniper.net/JSA106004
- supportportal.juniper.net https://supportportal.juniper.net/JSA106004
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.