CVE-2026-33788

HIGH

Junos OS Evolved: Local, authenticated attacker can gain privileged access to FPCs

Title source: cna
STIX 2.1

Description

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device. A local user with low privileges can gain direct access to the installed FPCs as a high privileged user, which can potentially lead to a full compromise of the affected component. This issue affects Junos OS Evolved on PTX10004, PTX10008, PTX100016, with JNP10K-LC1201 or JNP10K-LC1202: * All versions before 21.2R3-S8-EVO, * 21.4-EVO versions before 21.4R3-S7-EVO, * 22.2-EVO versions before 22.2R3-S4-EVO, * 22.3-EVO versions before 22.3R3-S3-EVO, * 22.4-EVO versions before 22.4R3-S2-EVO, * 23.2-EVO versions before 23.2R2-EVO.

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 3.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (6)
Juniper Networks/Junos OS Evolved < 21.2R3-S8-EVO
Juniper Networks/Junos OS Evolved 21.4-EVO - 21.4R3-S7-EVO
Juniper Networks/Junos OS Evolved 22.2-EVO - 22.2R3-S4-EVO
Juniper Networks/Junos OS Evolved 22.3-EVO - 22.3R3-S3-EVO
Juniper Networks/Junos OS Evolved 22.4-EVO - 22.4R3-S2-EVO
Juniper Networks/Junos OS Evolved 23.2-EVO - 23.2R2-EVO
Published Apr 09, 2026
Tracked Since Apr 10, 2026