CVE-2026-21913
7.5Juniper Networks · Junos OS (EX4000 series)
An incorrect initialization of resources in Juniper Networks Junos OS on EX4000 models allows an unauthenticated network attacker to trigger a device crash and denial of service.
Executive summary
A high-severity denial of service vulnerability exists in Juniper Networks Junos OS on EX4000 series switches that can be triggered by unauthenticated network traffic.
Vulnerability
This vulnerability involves incorrect resource initialization within the Internal Device Manager, which leads to an FXPC crash and system restart when the device is subjected to a high volume of traffic. The flaw is remotely exploitable by an unauthenticated, network-based attacker.
Business impact
The exploitation of this vulnerability results in a complete service outage for the affected EX4000-48T, EX4000-48P, and EX4000-48MP switch models until the hardware automatically completes a restart. With a CVSS score of 7.5, this high-severity flaw poses a significant risk to network availability and business continuity. Organizations relying on these switches for core connectivity may face operational downtime that disrupts mission-critical services.
Remediation
Immediate Action: Upgrade Junos OS to version 24.4R2, 25.2R1-S2, 25.2R2, 25.4R1, or any subsequent release as recommended by the vendor.
Proactive Monitoring: Monitor device logs for the error message "reason=0x4000002" or "watchdog + panic with core dump" via the "show chassis routing-engine" command to identify potential crash events.
Compensating Controls: Implement ingress rate limiting or traffic shaping on network interfaces to mitigate the impact of high-volume traffic spikes that trigger the underlying resource exhaustion.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for complete network disruption, administrators must prioritize the deployment of the provided firmware updates across all affected EX4000 series switches. Failure to patch these devices leaves the network infrastructure vulnerable to simple, high-volume traffic attacks that can be executed by unauthenticated remote actors.