CVE-2026-21920
HIGH EPSS 35.0%
Published Jan 15, 20265mo ago · Modified Jun 17, 20262w ago
8.7 CVSS 4.0
Published Jan 15, 2026 5mo ago
Last Modified Jun 17, 2026 2w ago
Description
An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series device configured for DNS processing, receives a specifically formatted DNS request flowd will crash and restart, which causes a service interruption until the process has recovered. This issue affects Junos OS on SRX Series: * 23.4 versions before 23.4R2-S5, * 24.2 versions before 24.2R2-S1, * 24.4 versions before 24.4R2. This issue does not affect Junos OS versions before 23.4R1.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X
Threat Intelligence
EPSS Exploit Probability
35.0% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-252
Affected Products 35
| Vendor | Product | Version | Range |
|---|---|---|---|
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 23.4 | any |
| juniper | junos | 24.2 | any |
| juniper | junos | 24.2 | any |
| juniper | junos | 24.2 | any |
| juniper | junos | 24.2 | any |
| juniper | junos | 24.2 | any |
| juniper | junos | 24.4 | any |
| juniper | junos | 24.4 | any |
| juniper | junos | 24.4 | any |
| juniper | junos | 24.4 | any |
| juniper | srx1500 | * | any |
| juniper | srx1600 | * | any |
| juniper | srx2300 | * | any |
| juniper | srx300 | * | any |
| juniper | srx320 | * | any |
| juniper | srx340 | * | any |
| juniper | srx345 | * | any |
| juniper | srx380 | * | any |
| juniper | srx4100 | * | any |
| juniper | srx4120 | * | any |
| juniper | srx4200 | * | any |
| juniper | srx4300 | * | any |
| juniper | srx4600 | * | any |
| juniper | srx4700 | * | any |
| juniper | srx5400 | * | any |
| juniper | srx5600 | * | any |
| juniper | srx5800 | * | any |
References 2
- kb.juniper.net https://kb.juniper.net/JSA106020
- supportportal.juniper.net https://supportportal.juniper.net/JSA106020
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.