CVE-2026-21913

An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on EX4000 models allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On EX4000 models with 48 ports (EX4000-48T, EX4000-48P, EX4000-48MP) a high volume of traffic destined to the device will cause an FXPC crash and restart, which leads to a complete service outage until the device has automatically restarted. The following reboot reason can be seen in the output of 'show chassis routing-engine' and as a log message:   reason=0x4000002 reason_string=0x4000002:watchdog + panic with core dump This issue affects Junos OS on EX4000-48T, EX4000-48P and EX4000-48MP: * 24.4 versions before 24.4R2, * 25.2 versions before 25.2R1-S2, 25.2R2. This issue does not affect versions before 24.4R1 as the first Junos OS version for the EX4000 models was 24.4R1.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:juniper:junos:24.4:-:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:24.4:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:24.4:r1-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:24.4:r1-s3:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:25.2:-:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:25.2:r1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:25.2:r1-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:25.2:r2:*:*:*:*:*:*
OR cpe:2.3:h:juniper:ex4000-48mp:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:ex4000-48p:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:ex4000-48t:-:*:*:*:*:*:*:*

History

17 Jun 2026, 10:19

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inicialización incorrecta de recursos en el Administrador de Dispositivos Internos (IDM) de Juniper Networks Junos OS en modelos EX4000 permite a un atacante no autenticado, basado en red, causar una Denegación de Servicio (DoS). En los modelos EX4000 con 48 puertos (EX4000-48T, EX4000-48P, EX4000-48MP), un alto volumen de tráfico destinado al dispositivo causará un fallo y reinicio de FXPC, lo que lleva a una interrupción completa del servicio hasta que el dispositivo se haya reiniciado automáticamente. La siguiente razón de reinicio se puede ver en la salida de 'show chassis routing-engine' y como un mensaje de registro: reason=0x4000002 reason_string=0x4000002:watchdog + panic with core dump Este problema afecta a Junos OS en EX4000-48T, EX4000-48P y EX4000-48MP: * versiones 24.4 anteriores a 24.4R2, * versiones 25.2 anteriores a 25.2R1-S2, 25.2R2. Este problema no afecta a las versiones anteriores a 24.4R1, ya que la primera versión de Junos OS para los modelos EX4000 fue 24.4R1.

23 Jan 2026, 19:40

Type Values Removed Values Added
First Time Juniper ex4000-48mp
Juniper ex4000-48p
Juniper ex4000-48t
Juniper junos
Juniper
CWE CWE-665
CPE cpe:2.3:h:juniper:ex4000-48mp:-:*:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:25.2:r2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:24.4:r1-s3:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:25.2:r1:*:*:*:*:*:*
cpe:2.3:h:juniper:ex4000-48p:-:*:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:24.4:r1:*:*:*:*:*:*
cpe:2.3:h:juniper:ex4000-48t:-:*:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:24.4:r1-s2:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:24.4:-:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:25.2:r1-s1:*:*:*:*:*:*
cpe:2.3:o:juniper:junos:25.2:-:*:*:*:*:*:*
References () https://kb.juniper.net/JSA106014 - () https://kb.juniper.net/JSA106014 - Vendor Advisory
References () https://supportportal.juniper.net/JSA106014 - () https://supportportal.juniper.net/JSA106014 - Vendor Advisory

15 Jan 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 21:16

Updated : 2026-06-17 10:19


NVD link : CVE-2026-21913

Mitre link : CVE-2026-21913

CVE.ORG link : CVE-2026-21913


JSON object : View

Products Affected

juniper

  • ex4000-48t
  • ex4000-48mp
  • ex4000-48p
  • junos
CWE
CWE-665

Improper Initialization