CVE-2026-33788
7.8Juniper Networks · Junos OS Evolved
A missing authentication flaw in Juniper Junos OS Evolved on PTX series devices allows local, low privileged users to gain unauthorized high-privileged access to Flexible PIC Concentrators.
Executive summary
A missing authentication vulnerability in Juniper Networks Junos OS Evolved allows local attackers to elevate privileges and gain unauthorized access to critical hardware components, creating a risk of full component compromise.
Vulnerability
This is a missing authentication for critical function (CWE-306) flaw. It enables an authenticated local user with low privileges to bypass security controls and interact with Flexible PIC Concentrators as a high-privileged user.
Business impact
The vulnerability carries a CVSS score of 7.8, reflecting a High severity rating due to the potential for total compromise of the affected hardware component. Successful exploitation allows a malicious actor to gain administrative control over the FPC, which could lead to unauthorized network traffic manipulation, denial of service, or lateral movement within the infrastructure.
Remediation
Immediate Action: Upgrade affected Junos OS Evolved instances to the corrected releases: 21.2R3-S8-EVO, 21.4R3-S7-EVO, 22.2R3-S4-EVO, 22.3R3-S3-EVO, 22.4R3-S2-EVO, 23.2R2-EVO, 23.4R1-EVO, or any subsequent release.
Proactive Monitoring: Review system access logs for unauthorized attempts to access FPC management interfaces or unexpected privilege escalation events involving low-level user accounts.
Compensating Controls: Restrict physical and logical access to the device management plane to only essential personnel to limit the exposure to potential local attackers.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for full compromise of the affected Flexible PIC Concentrators, organizations operating PTX series hardware should prioritize patching during the next maintenance window. Apply the recommended firmware updates provided by Juniper Networks to eliminate the vulnerability and ensure the integrity of the device management plane.