CVE-2026-21914 describes an Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series devices. An unauthenticated, network-based attacker can trigger a Denial-of-Service (DoS) by sending a specially malformed GPRS Tunnelling Protocol (GTP) Modify Bearer Request message, causing the device to crash and restart. This vulnerability has a CVSS score of 7.5 (High), indicating a low attack complexity and high impact on availability, leading to a complete traffic outage. There is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, though community discussion shows 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 22.4R3-S8CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 23.2, < 23.2R2-S5CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 23.4, < 23.4R2-S6CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 24.2, < 24.2R2-S3CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 24.4, < 24.4R2-S2CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.