Cyber Resilience

CVE-2026-33773

Juniper Junos 23.4 … 24.2

Published
09 April 2026
Modified
17 April 2026
Patch / advisory
CVSS Score v4 6.9
Click a component to see what it means
Raw vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X
EPSS Score 0.0020 10th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2026-33773 is a medium-severity an unspecified weakness vulnerability in Juniper Junos. Its CVSS base score is 6.9 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 10th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and SI-2 (Flaw Remediation) — see the control section below for these in your framework.

EU & UK References

Vulnerability Data

An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device allows an unauthenticated, network-based attacker to cause an integrity impact to downstream networks. When the…

more

same family inet or inet6 filter is applied on an IRB interface and on a physical interface as egress filter on EX4100, EX4400, EX4650 and QFX5120 devices, only one of the two filters will be applied, which can lead to traffic being sent out one of these interfaces which should have been blocked. This issue affects Junos OS on EX Series and QFX Series: * 23.4 version 23.4R2-S6, * 24.2 version 24.2R2-S3. No other Junos OS versions are affected.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

Vulnerability in network device packet filter application enables remote unauthenticated exploitation to bypass egress filtering controls.

Confidence: MEDIUM · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2026-33781Same product: Juniper Ex4000
CVE-2026-21910Same product: Juniper Ex4000
CVE-2026-57025Same product: Juniper Ex2300
CVE-2024-30388Same product: Juniper Ex4100
CVE-2025-30644Same product: Juniper Ex2300
CVE-2026-33774Same product: Juniper Junos
CVE-2026-57054Same product: Juniper Junos
CVE-2025-6549Same product: Juniper Junos
CVE-2025-59968Same vendor: Juniper
CVE-2026-33803Same vendor: Juniper

Affected Assets

juniper
junos
23.4, 24.2

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • AC-3 Access Enforcement
  • SI-2 Flaw Remediation
  • AC-4 Information Flow Enforcement
Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly enforces the intended egress filter rules on IRB and physical interfaces that the flawed PFE initialization failed to apply.

prevent

Requires timely patching of the Junos OS versions containing the incorrect filter-initialization flaw.

prevent

Enforces information-flow policies via firewall filters; the CVE is a failure of that enforcement on affected devices.

References