CVE-2026-57032CWE-236

Junos OS: EX Series: Subscribing to an unsupported telemetry sensor path causes fxpc process crash

High · published July 9, 2026

CVSS v4.0
7.1
EPSS
0%
Percentile
35.1
In the wild
Unconfirmed
What it is

An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low privileges to cause a Denial-of-Service (DoS).

If an attempt is made to subscribe to an unsupported telemetry sensor path on EX2300, EX3400, EX4000, EX4100 and EX4400 via gRPC, this causes the FPC to crash. This leads to a complete service outage until the module has automatically restarted.

The following log message can be seen when this issue happens:

agentd[<PID>]: AGENTD_RESOURCE_NOT_FOUND: No resource name found for <sensor>

This issue affects Junos OS on

EX2300, EX3400, EX4000, EX4100 and EX4400

devices:

* all versions before 23.2R2-S7,

* 23.4 versions before 23.4R2-S8,

* 24.2 versions before 24.2R2-S5,

* 24.4 versions before 24.4R2.

The record
Technical detail
CVSS v4.0
7.1 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M
EPSS
0.00420 · 35.1th percentile
Weakness
CWE-236 · Improper Handling of Undefined Parameters
Published
2026-07-09T21:14Z
EPSS history
Timeline
  • 09 JUL 21:14Z
    Junos OS: EX Series: Subscribing to an unsupported telemetry sensor path causes fxpc process crash
    cvelistv5