CVE-2026-21913CWE-1419

Junos OS: EX4000: A high volume of traffic destined to the device leads to a crash and restart

High · published January 15, 2026

CVSS v4.0
8.7
EPSS
0%
Percentile
32.1
In the wild
Unconfirmed
What it is

⚡ A high volume of traffic can send your Junos OS EX4000 models crashing down like a house of cards! 🏰 Think of the Internal Device Manager (IDM) like a busy restaurant kitchen. If too many orders come in at once without proper management, it leads to chaos and a complete service shutdown until the chaos is sorted out and they can get back on track. In this case, an unauthenticated attacker can flood the system with traffic, causing a Denial-of-Service (DoS) which leads to a full restart of the device. This means all your services are offline until the device can reboot, creating potentially devastating downtime for your network and operations.

Put simply

Think of the Internal Device Manager (IDM) like a busy restaurant kitchen. If too many orders come in at once without proper management, it leads to chaos and a complete service shutdown until the chaos is sorted out and they can get back on track. This vulnerability arises from an Incorrect Initialization of Resource within the IDM of Junos OS on specific EX4000 models. The issue allows an attacker to overwhelm the device, leading to a crash and subsequent restart, indicated by a specific watchdog panic log message.

What to do

In this case, an unauthenticated attacker can flood the system with traffic, causing a Denial-of-Service (DoS) which leads to a full restart of the device. This means all your services are offline until the device can reboot, creating potentially devastating downtime for your network and operations. Immediate action is required! Update your Junos OS to version 24.4R2 for 24.4 versions and 25.2R1-S2 or 25.2R2 for 25.2 versions. Regularly monitor your network traffic to identify and mitigate potential attacks before they escalate. You've got this! By staying ahead of the patching process, you'll ensure your network remains safe and sound. 🛡️

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M
EPSS
0.00390 · 32.1th percentile
Weakness
CWE-1419 · Incorrect Initialization of Resource
Published
2026-01-15T20:25Z
EPSS history
Timeline
  • 15 JAN 20:25Z
    Junos OS: EX4000: A high volume of traffic destined to the device leads to a crash and restart
    cvelistv5