Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33775

22
FAUCET Score

OVERVIEW CVE-2026-33775 is a memory leak vulnerability in the BroadBand Edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS affecting MX Series routers. When the authentication packet-type option is configured and received packets fail to match the specified packet type, the daemon fails to release allocated memory. This memory exhaustion prevents new subscribers from logging in once available heap memory is depleted. The vulnerability impacts multiple Junos OS versions across several release branches, with patched versions available for 22.4, 23.2, 23.4, 24.2, 24.4, and 25.2 series. SEVERITY The vulnerability carries a CVSS score of 6.5 (Medium) with an adjacent network attack vector requiring no authentication or user interaction. Attack complexity is low, meaning an unauthenticated attacker positioned on the local network can trigger the memory leak reliably. The impact is limited to availability, as the attack causes service denial by exhausting daemon memory resources rather than compromising confidentiality or integrity. The EPSS score of 0.00028 indicates minimal real-world exploitation activity relative to other vulnerabilities. EXPLOITATION STATUS There is no evidence of active exploitation, and the vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog. No publicly available exploit code has been reported. The relatively low FAUCET Risk Score of 44.0 and inactive status on security hot lists suggest limited community and threat actor attention, though organizations running vulnerable versions should apply available patches to maintain operational resilience.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 22.4R3-S8CPE match
cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*
>= 23.2, < 23.2R2-S5CPE match
cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*
>= 23.4, < 23.4R2-S6CPE match
cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*
>= 24.2, < 24.2R2-S2CPE match
cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*
>= 24.4, < 24.4R2CPE match
cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.1HIGH

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X

Attack Vector
ADJACENT
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.19%
Probability of exploitation in next 30 days
EPSS Percentile
9.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 11th percentile among its peer group of 1,802 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

junipervendor investigatingvia vendor_rss
View patch

Vendor Advisories (1)

juniperjuniper:ka0Dp000000vCXyIAM

2026-04 Security Bulletin: Junos OS: MX Series: Mismatch between configured and received packet types causes memory leak in bbe-smgd (CVE-2026-33775)

Apr 8, 2026

References

kb.juniper.net / JSA107821
Vendor Advisory