CVE-2026-33773 is an Incorrect Initialization of Resource vulnerability affecting Juniper Networks Junos OS on specific EX Series and QFX Series switches (EX4100, EX4400, EX4650, and QFX5120). When identical inet or inet6 filters are applied to both IRB interfaces and physical interfaces as egress filters on these devices, only one filter is enforced, allowing traffic that should be blocked to be transmitted out of the affected interface. The vulnerability impacts Junos OS versions 23.4R2-S6 and 24.2R2-S3, with no other versions affected. The vulnerability carries a CVSS score of 5.8 (Medium severity) with a network-based attack vector requiring no authentication or user interaction. The attack has low complexity and results in a limited integrity impact to downstream networks, with no confidentiality or availability implications. The scope is considered changed, indicating potential impact beyond the vulnerable component itself. This vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation. The EPSS score of 0.00047 indicates minimal community exploitation activity, ranking lower than approximately 99.86 percent of published CVEs. No public exploit code has been identified, and overall community attention appears limited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 23.4R2-S6, < 23.4R2-S7CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 24.2R2-S3, < 24.2R2-S4CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
23.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:23.4:r2-s6:*:*:*:*:*:* | ||
24.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos:24.2:r2-s3:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.