CVE-2026-57020
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).
On all QFX10000 platforms in an EVPN-VxLAN scenario, if an attacker sends IPv6 multicast traffic and these packets reach the non-IRB interface of a spine switch it floods the packet to other spines and all Ethernet Segment Identifier (ESI) leaf switches. This flooding causes the packet to be forwarded in a endless loop, which can lead to saturation of the involved links and in turn impact to legitimate traffic.
Leer descripción completaMostrar menos
This issue affects Junos OS on QFX10000 Series:
This issue does not affect Junos version after 24.4 as the QFX10000 Series devices are not supported on newer versions anymore.
Detalles técnicos trazas, registros y código del informe original
* all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S4.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.27%
- Percentil entre todas las CVEs puntuadas: 17
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1499.004Application or System Exploitationimpact90 %
Atacante adyacente no autenticado envía tráfico IPv6 multicast a red EVPN-VxLAN causando bucle infinito de forwarding (AV:A, PR:N, UI:N). Resultado: saturación de enlaces y DoS (VI:N, VA:H, SA:L indican disponibilidad). T1499.004 (network flood).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-754
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-57020",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-57020",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-07-10T13:28:54.914596Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "sirt@juniper.net",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "sirt@juniper.net",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "USER",
"baseScore": 7.1,
"Automatable": "YES",
"attackVector": "ADJACENT",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "LOW",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "MODERATE",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "sirt@juniper.net",
"affectedData": [
{
"vendor": "Juniper Networks",
"product": "Junos OS",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "23.2R2-S7",
"versionType": "custom"
},
{
"status": "affected",
"version": "23.4",
"lessThan": "23.4R2-S8",
"versionType": "custom"
},
{
"status": "affected",
"version": "24.2",
"lessThan": "24.2R2-S4",
"versionType": "custom"
},
{
"status": "affected",
"version": "24.4",
"lessThan": "24.4R2-S4",
"versionType": "custom"
}
],
"platforms": [
"QFX10000 Series"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-07-09T22:17:06.887",
"references": [
{
"url": "https://supportportal.juniper.net/JSA110080",
"tags": [
"Vendor Advisory"
],
"source": "sirt@juniper.net"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "sirt@juniper.net",
"description": [
{
"lang": "en",
"value": "CWE-754"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).\n\nOn all QFX10000 platforms in an EVPN-VxLAN scenario, if an attacker sends IPv6 multicast traffic and these packets reach the non-IRB interface of a spine switch it floods the packet to other spines and all Ethernet Segment Identifier (ESI) leaf switches. This flooding causes the packet to be forwarded in a endless loop, which can lead to saturation of the involved links and in turn impact to legitimate traffic.\n\n\n\nThis issue affects Junos OS on QFX10000 Series:\n\n\n * all versions before 23.2R2-S7,\n * 23.4 versions before 23.4R2-S8,\n * 24.2 versions before 24.2R2-S4,\n * 24.4 versions before 24.4R2-S4.\n\n\n\nThis issue does not affect Junos version after 24.4 as the QFX10000 Series devices are not supported on newer versions anymore."
}
],
"lastModified": "2026-07-13T20:57:06.157",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3D14745F-3090-483F-9DB4-C424FA09BD21",
"versionEndExcluding": "23.2"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A78CC80-E8B1-4CDA-BB35-A61833657FA7"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B3B2FE1-C228-46BE-AC76-70C2687050AE"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r1-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F1B16FF0-900F-4AEE-B670-A537139F6909"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r1-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B227E831-30FF-4BE1-B8B2-31829A5610A6"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1ADA814B-EF98-45B1-AF7A-0C89688F7CA5"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r2-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A6FB32DF-D062-4FB9-8777-452978BEC7B7"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r2-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B3B6C811-5C10-4486-849D-5559B592350A"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r2-s3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "078D61B9-A228-453C-9D20-6F9C6B20637F"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r2-s4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F1F136A0-021D-43FE-BDD3-AD7201F7FC03"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r2-s5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37147BC9-9ED8-48AE-906A-614AD8600962"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.2:r2-s6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7897729C-4128-49E9-B4A1-25353BC4DBB2"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "78481ABC-3620-410D-BC78-334657E0BB75"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE8A5BA3-87BD-473A-B229-2AAB2C797005"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r1-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8B74AC3E-8FC9-400A-A176-4F7F21F10756"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r1-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB2D1FCE-8019-4CE1-BA45-D62F91AF7B51"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "175CCB13-76C0-44A4-A71D-41E22B92EB23"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r2-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "166BFDB3-1945-4949-BC2B-E18442FF2E4D"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r2-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5923610F-878C-48CA-8B5D-9C609E4DD4DB"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r2-s3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A7C207E3-0252-4192-8E8C-E2ED2831B4F4"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r2-s4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E6974492-FE69-4340-8881-61C3329C1545"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r2-s5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "279E59FE-96DF-4E1D-A3A2-61D180F04533"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r2-s6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D9A36E5-A1BB-46E1-91B6-91A4C40C1B59"
},
{
"criteria": "cpe:2.3:o:juniper:junos:23.4:r2-s7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A46347EE-31C0-4D06-A862-536789F4F823"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.2:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89524D6D-0B22-4952-AD8E-8072C5A05D5C"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.2:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD69A194-1B03-44EA-8092-79BD10C6F729"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.2:r1-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8463ADB4-B8A7-4D63-97A9-232ED713A21C"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.2:r1-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE68337F-106E-4317-A5B6-292B0159F577"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.2:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "266B520A-482A-43F7-90F8-B9D64D30034F"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.2:r2-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC78BC9E-5DA7-4E42-9923-B49A0B7F3564"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.2:r2-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DD99F1B0-82B0-4CD3-8C8F-C0FFF44A8B90"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.2:r2-s3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "619B5EA0-0369-4AFE-AD8B-A3A22B326F9E"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C452BDCB-34E3-42D3-8909-2312356EB70A"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.4:r1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B8158F2-2028-40E9-955F-CFD581A32F60"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.4:r1-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A7233A1-EC7A-4458-9AE1-835480A03A21"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.4:r1-s3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D74087E2-5CAA-4085-8408-EB70EC1D5D91"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.4:r2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0EEF1798-F3C2-4645-96E7-1E82368B184D"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.4:r2-s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C8BB5EE1-04C7-4DF3-807A-06005ECFEEE5"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.4:r2-s2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4C707226-9C89-4D06-8E8F-2071061E6F2A"
},
{
"criteria": "cpe:2.3:o:juniper:junos:24.4:r2-s3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3C0C59A7-D826-4D14-AE46-2CA9D0900BC3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:juniper:qfx10008:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1453E42A-77B3-4922-8EC3-1A5668C39550"
},
{
"criteria": "cpe:2.3:h:juniper:qfx10016:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "26408465-BD6A-4416-B98E-691A5F651080"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "sirt@juniper.net"
}