CVE-2026-21917

7.5

Juniper Networks · Junos OS

A malformed SSL packet can trigger a crash in the Web-Filtering module of Juniper Networks Junos OS on SRX Series devices, leading to an unauthenticated denial-of-service condition.

Executive summary

A critical denial-of-service vulnerability in Juniper Networks Junos OS allows unauthenticated network attackers to crash SRX Series devices via malformed SSL traffic.

Vulnerability

This flaw involves improper validation of input syntactic correctness within the Web-Filtering module. An unauthenticated attacker can send a specifically malformed SSL packet to an SRX device configured for UTM Web-Filtering, causing an FPC crash and subsequent device restart.

Business impact

Successful exploitation of this vulnerability results in a denial-of-service, which can disrupt critical network traffic and security services provided by SRX gateways. Given the CVSS score of 7.5, this high-severity issue poses a significant risk to operational continuity, as an attacker can repeatedly force device reboots to maintain an offline state for internal network segments.

Remediation

Immediate Action: Upgrade Junos OS to the patched releases: 23.2R2-S5, 23.4R2-S5, 24.2R2-S2, 24.4R1-S3, 24.4R2, 25.2R1, or any subsequent version.

Proactive Monitoring: Monitor system logs for frequent FPC (Flexible PIC Concentrator) crashes, unexpected device restarts, or spikes in malformed traffic patterns targeting the security gateway.

Compensating Controls: If immediate patching is not feasible, consider disabling the affected Web-Filtering feature if it is not critical to operations, or utilize upstream ACLs to restrict traffic reaching the SRX management and traffic-processing interfaces.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk of service disruption to SRX Series firewalls necessitates prompt attention. Administrators should prioritize the deployment of the provided vendor security updates to eliminate the underlying vulnerability and prevent potential service outages caused by malicious SSL traffic.

More Juniper Networks CVEs

Sources