CVE-2026-33787

MEDIUM

Junos OS: SRX1500, SRX4100, SRX4200, SRX4600: When a specific show command is executed chassisd crashes

Title source: cna
STIX 2.1

Description

An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1500, SRX4100, SRX4200 and SRX4600 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts which causes a momentary impact to all traffic until all modules are online again. This issue affects Junos OS on SRX1500, SRX4100, SRX4200 and SRX4600:  * 23.2 versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S7 * 24.2 versions before 24.2R2-S2, * 24.4 versions before 24.4R2, * 25.2 versions before 25.2R1-S1, 25.2R2.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 2.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (10)
juniper/junos 23.2 (10 CPE variants)
juniper/junos 23.4 (11 CPE variants)
juniper/junos 24.2 (6 CPE variants)
juniper/junos 24.4 (4 CPE variants)
juniper/junos 25.2 (3 CPE variants)
Juniper Networks/Junos OS < 23.2R2-S6
Juniper Networks/Junos OS 23.4 - 23.4R2-S7
Juniper Networks/Junos OS 24.2 - 24.2R2-S2
Juniper Networks/Junos OS 24.4 - 24.4R2
Juniper Networks/Junos OS 25.2 - 25.2R1-S1, 25.2R2
Published Apr 09, 2026
Tracked Since Apr 10, 2026