OVERVIEW CVE-2026-33775 is a memory leak vulnerability in the BroadBand Edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS affecting MX Series routers. When the authentication packet-type option is configured and received packets fail to match the specified packet type, the daemon fails to release allocated memory. This memory exhaustion prevents new subscribers from logging in once available heap memory is depleted. The vulnerability impacts multiple Junos OS versions across several release branches, with patched versions available for 22.4, 23.2, 23.4, 24.2, 24.4, and 25.2 series. SEVERITY The vulnerability carries a CVSS score of 6.5 (Medium) with an adjacent network attack vector requiring no authentication or user interaction. Attack complexity is low, meaning an unauthenticated attacker positioned on the local network can trigger the memory leak reliably. The impact is limited to availability, as the attack causes service denial by exhausting daemon memory resources rather than compromising confidentiality or integrity. The EPSS score of 0.00028 indicates minimal real-world exploitation activity relative to other vulnerabilities. EXPLOITATION STATUS There is no evidence of active exploitation, and the vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog. No publicly available exploit code has been reported. The relatively low FAUCET Risk Score of 44.0 and inactive status on security hot lists suggest limited community and threat actor attention, though organizations running vulnerable versions should apply available patches to maintain operational resilience.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 22.4R3-S8CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 23.2, < 23.2R2-S5CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 23.4, < 23.4R2-S6CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 24.2, < 24.2R2-S2CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 24.4, < 24.4R2CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.