CVE-2026-21913
Last modified
CVE-2026-21913 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on EX4000 models allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On EX4000 models with 48 ports (EX4000-48T, EX4000-48P, EX4000-48MP) a high volume of traffic destined to the device will cause an FXPC crash and restart, which leads to a complete service outage until the device has automatically restarted. The following reboot reason can be seen in the output of 'show chassis routing-engine' and as a log message: reason=0x4000002 reason_string=0x4000002:watchdog + panic with core dump This issue affects Junos OS on EX4000-48T, EX4000-48P and EX4000-48MP: * 24.4 versions before 24.4R2, * 25.2 versions before 25.2R1-S2, 25.2R2. This issue does not affect versions before 24.4R1 as the first Junos OS version for the EX4000 models was 24.4R1.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on EX4000 models allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On EX4000 models with 48 ports (EX4000-48T, EX4000-48P, EX4000-48MP) a high volume of traffic destined to the device will cause an FXPC crash and restart, which leads to a complete service outage until the device has automatically restarted. The following reboot reason can be seen in the output of 'show chassis routing-engine' and as a log message: reason=0x4000002 reason_string=0x4000002:watchdog + panic with core dump This issue affects Junos OS on EX4000-48T, EX4000-48P and EX4000-48MP: * 24.4 versions before 24.4R2, * 25.2 versions before 25.2R1-S2, 25.2R2. This issue does not affect versions before 24.4R1 as the first Junos OS version for the EX4000 models was 24.4R1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | 24.4 |
| Juniper | Junos | 25.2 |
References
- https://kb.juniper.net/JSA106014Vendor Advisory
- https://supportportal.juniper.net/JSA106014Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-21913?
How severe is CVE-2026-21913?
How do I fix CVE-2026-21913?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-21908A Use After Free vulnerability was identified in the 802.1X …7.5
- CVE-2026-21909A Missing Release of Memory after Effective Lifetime vulnera…7.1
- CVE-2026-2191A weakness has been identified in Tenda AC9 15.03.06.42_mult…7.3
- CVE-2026-21910An Improper Check for Unusual or Exceptional Conditions vuln…7.1
- CVE-2026-21911An Incorrect Calculation vulnerability in the Layer 2 Contro…7.1
- CVE-2026-21912A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerab…4.7
- CVE-2026-21914An Improper Locking vulnerability in the GTP plugin of Junip…8.7
- CVE-2026-21915A Permissive List of Allowed Input vulnerability in the CLI …8.4
- CVE-2026-21916A UNIX Symbolic Link (Symlink) Following vulnerability in th…7.3
- CVE-2026-21917An Improper Validation of Syntactic Correctness of Input vul…8.7
- CVE-2026-21918A Double Free vulnerability in the flow processing daemon (f…8.7
- CVE-2026-21919An Incorrect Synchronization vulnerability in the management…7.1
Are you affected by CVE-2026-21913?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
