CVE-2026-57024
Last modified
CVE-2026-57024 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On an MX with SPC3 and SRX devices configured for VPN service, when a large number of VPN negotiations fail a peer index rollover will eventually occur. As a result, new peers are assigned index values that are already in use and the iked process starts to crash repeatedly. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On an MX with SPC3 and SRX devices configured for VPN service, when a large number of VPN negotiations fail a peer index rollover will eventually occur. As a result, new peers are assigned index values that are already in use and the iked process starts to crash repeatedly. This results in failure to establish new VPN connections and rekeying existing ones. To restore service the system must be rebooted. Please note that the index value can't be monitored, so customers should monitor tunnel up and down events and if a lot of events occur over an extended period of time it becomes likely that this issue occurs. To be exposed to this issue the system needs to run iked (vs. kmd which is not affected), which can be verified with: user@host> show system processes extensive | match "KMD|IKED" This issue affects Junos OS on MX with SPC3, SRX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S6, * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R1-S1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | < 23.2 |
| Juniper | Junos | 23.2 |
| Juniper | Junos | 23.4 |
| Juniper | Junos | 24.2 |
| Juniper | Junos | 24.4 |
| Juniper | Junos | 25.2 |
References
- https://supportportal.juniper.net/JSA110084Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-57024?
How severe is CVE-2026-57024?
How do I fix CVE-2026-57024?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-56968GNU SASL before 2.2.4 lacks sanitization of a short challeng…5.3
- CVE-2026-57019An Improper Validation of Specified Quantity in Input vulner…7.1
- CVE-2026-57020An Improper Check for Unusual or Exceptional Conditions vuln…7.1
- CVE-2026-57021An Out-of-bounds Write vulnerability in the http-gatekeeper …6.9
- CVE-2026-57022An Improper Check for Unusual or Exceptional Conditions vuln…8.2
- CVE-2026-57023An Improper Validation of Specified Quantity in Input vulner…8.7
- CVE-2026-57025A Return of Pointer Value Outside of Expected Range vulnerab…6.8
- CVE-2026-57026An Improper Validation of Syntactic Correctness of Input vul…8.7
- CVE-2026-57027A Missing Release of Memory after Effective Lifetime vulnera…7.1
- CVE-2026-57028An Improper Restriction of Communication Channel to Intended…7.3
- CVE-2026-57029A Missing Synchronization vulnerability in the flow collecto…6
- CVE-2026-57030A Concurrent Execution using Shared Resource with Improper S…8.2
Are you affected by CVE-2026-57024?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
