Junos OS: EX Series: Unauthorized users can execute service-impacting CLI command
Published Jul 9, 2026
6.8
MEDIUMCVSS 4.0
EPSS 0.12%
Description
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS).
On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, local attacker with no specific permissions or class can execute a specific, privileged CLI 'request' command which will cause complete traffic impact until the system automatically recovers.
This issue affects Junos OS on EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400:
* 23.2R2 versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R2, * 25.4 versions before 25.4R1-S1.
Affected products
-
- Version 23.2R2StatusaffectedConstraints<23.2R2-S6
- Version 23.4StatusaffectedConstraints<23.4R2-S8
- Version 24.2StatusaffectedConstraints<24.2R2-S4
- Version 24.4StatusaffectedConstraints<24.4R2-S3
- Version 25.2StatusaffectedConstraints<25.2R2
- Version 25.4StatusaffectedConstraints<25.4R1-S1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Juniper Networks | Junos OS | unaffected |
|
- 23.2
- 23.2
- 23.2
- 23.2
- 23.2
- 23.2
- 23.4
- 23.4
- 23.4
- 23.4
- 23.4
- 23.4
- 23.4
- 23.4
- 23.4
- 23.4
- 23.4
- 23.4
- 24.2
- 24.2
- 24.2
- 24.2
- 24.2
- 24.2
- 24.2
- 24.2
- 24.4
- 24.4
- 24.4
- 24.4
- 24.4
- 24.4
- 24.4
- 25.2
- 25.2
- 25.2
- 25.2
- 25.4
- 25.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The following software releases have been updated to resolve this specific issue:
Junos OS: 23.2R2-S6, 23.4R2-S8, 24.2R2-S4, 24.4R2-S3, 25.2R2, 25.4R1-S1, 25.4R2, 26.2R1, and all subsequent releases.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42703 Advisory
- https://supportportal.juniper.net/JSA110077 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42703 | Advisory | |
| https://supportportal.juniper.net/JSA110077 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.