{
  "document" : {
    "aggregate_severity" : {
      "text" : "hoch"
    },
    "category" : "csaf_base",
    "csaf_version" : "2.0",
    "distribution" : {
      "tlp" : {
        "label" : "WHITE",
        "url" : "https://www.first.org/tlp/"
      }
    },
    "lang" : "de-DE",
    "notes" : [ {
      "category" : "legal_disclaimer",
      "text" : "Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen."
    }, {
      "category" : "description",
      "text" : "JUNOS ist das \"Juniper Network Operating System\", das in Juniper Appliances verwendet wird.\r\nBei den Switches der Juniper EX-Serie handelt es sich um Access- und Aggregations-/Core-Layer-Switches.\r\nDie Juniper MX-Serie ist eine Produktfamilie von Routern.\r\nDie Switches der QFX-Serie von Juniper sichern und automatisieren Netzwerke in Rechenzentren. \r\nSRX Series Services Gateways ist ein Next-Generation Anti-Threat Firewall von Juniper.",
      "title" : "Produktbeschreibung"
    }, {
      "category" : "summary",
      "text" : "Ein Angreifer kann mehrere Schwachstellen in Juniper JUNOS, JUNOS Evolved, Juniper EX Series, Juniper MX Series, Juniper QFX Series und Juniper SRX Series ausnutzen, um einen Denial of Service Zustand herbeizuführen, um Informationen offenzulegen, um Code auszuführen und um ein undefiniertes Verhalten auszulösen.",
      "title" : "Angriff"
    }, {
      "category" : "general",
      "text" : "- Juniper Appliance",
      "title" : "Betroffene Betriebssysteme"
    } ],
    "publisher" : {
      "category" : "other",
      "contact_details" : "csaf-provider@cert-bund.de",
      "name" : "Bundesamt für Sicherheit in der Informationstechnik",
      "namespace" : "https://www.bsi.bund.de"
    },
    "references" : [ {
      "category" : "self",
      "summary" : "WID-SEC-W-2026-2257 - CSAF Version",
      "url" : "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2257.json"
    }, {
      "category" : "self",
      "summary" : "WID-SEC-2026-2257 - Portal Version",
      "url" : "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2257"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletins vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/global-search/%40uri#q=Junos%20OS&sortCriteria=date%20descending&f-sf_articletype=Security%20Advisories&numberOfResults=50"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS and Junos OS Evolved: Configuration of a specific SSH option results in mgd crash (CVE-2026-21901) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-Configuration-of-a-specific-SSH-option-results-in-mgd-crash-CVE-2026-21901"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning' command causes l2ald crash (CVE-2026-57025) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-EX-Series-QFX-Series-MX-Series-A-specific-show-l2-learning-command-causes-l2ald-crash-CVE-2026-57025"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results in memory leak and eventual snmpd crash (CVE-2026-33799) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-Receipt-of-a-specific-SNMPv3-request-results-in-memory-leak-and-eventual-snmpd-crash-CVE-2026-33799"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS and Junos OS Evolved: When a specifically malformed BGP route update is received RPD crashes (CVE-2026-33801) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-When-a-specifically-malformed-BGP-route-update-is-received-RPD-crashes-CVE-2026-33801"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker (CVE-2026-33803) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-Evolved-A-port-which-has-been-inadvertently-exposed-can-be-reached-by-an-attacker-CVE-2026-33803"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker (CVE-2026-57028) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-Evolved-A-port-which-has-been-inadvertently-exposed-can-be-reached-by-an-attacker-CVE-2026-57028"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS Evolved: PTX Series: Receipt of repeated ECMP routing updates results in PFE crash (CVE-2026-33794) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-Evolved-PTX-Series-Receipt-of-repeated-ECMP-routing-updates-results-in-PFE-crash-CVE-2026-33794"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash (CVE-2026-57029) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-Evolved-QFX-Series-When-sFlow-collector-reachability-changes-evo-pfemand-process-can-crash-CVE-2026-57029"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS Evolved: URL handling vulnerability in libfetch results in heap buffer overflow (CVE-2020-7450) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-Evolved-URL-handling-vulnerability-in-libfetch-results-in-heap-buffer-overflow-CVE-2020-7450"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: EX4100 Series, EX4400: With sFlow configured in a VC scenario multicast traffic leads to an FPC crash (CVE-2026-57027) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-EX4100-Series-EX4400-With-sFlow-configured-in-a-VC-scenario-multicast-traffic-leads-to-an-FPC-crash-CVE-2026-57027"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: EX Series: Subscribing to an unsupported telemetry sensor path causes fxpc process crash (CVE-2026-57032) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-EX-Series-Subscribing-to-an-unsupported-telemetry-sensor-path-causes-fxpc-process-crash-CVE-2026-57032"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: EX Series: Unauthorized users can execute service-impacting CLI command (CVE-2026-33802) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-EX-Series-Unauthorized-users-can-execute-service-impacting-CLI-command-CVE-2026-33802"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: MX Series: For subscribers configured on static interfaces, input filters are not in effect (CVE-2026-57031) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-MX-Series-For-subscribers-configured-on-static-interfaces-input-filters-are-not-in-effect-CVE-2026-57031"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps will cause an FPC crash (CVE-2026-33800) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-MX-Series-In-a-VC-scenario-a-high-rate-of-micro-BFD-session-flaps-will-cause-an-FPC-crash-CVE-2026-33800"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: MX Series: Specific traffic causes an FPC to reset (CVE-2026-57019) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-MX-Series-Specific-traffic-causes-an-FPC-to-reset-CVE-2026-57019"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs (CVE-2026-57054) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-MX-Series-Web-filtering-doesn-t-block-specifically-formatted-URLs-CVE-2026-57054"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: MX Series with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd crash (CVE-2026-57023) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-MX-Series-with-SPC3-SRX-Series-A-specifically-malformed-TCP-packet-causes-a-flowd-crash-CVE-2026-57023"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash (CVE-2026-57026) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-MX-Series-with-SPC3-SRX-Series-Processing-of-a-specifically-malformed-SIP-invite-causes-a-flowd-crash-CVE-2026-57026"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: MX Series with SPC3, SRX Series: Specific packet in response to a TCP connection establishment by the affected device can crash the PFE (CVE-2026-57022) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-MX-Series-with-SPC3-SRX-Series-Specific-packet-in-response-to-a-TCP-connection-establishment-by-the-affected-device-can-crash-the-PFE-CVE-2026-57022"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously (CVE-2026-57024) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-MX-with-SPC3-SRX-Series-Repeated-VPN-negotiation-failures-will-eventually-cause-iked-to-crash-continuously-CVE-2026-57024"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: QFX10000 Series: IPv6 multicast traffic received on non-IRB interfaces causes a multicast flood (CVE-2026-57020) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-QFX10000-Series-IPv6-multicast-traffic-received-on-non-IRB-interfaces-causes-a-multicast-flood-CVE-2026-57020"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: SRX Series: Flow sessions are not getting cleared leading to a DoS (CVE-2026-57030) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-SRX-Series-Flow-sessions-are-not-getting-cleared-leading-to-a-DoS-CVE-2026-57030"
    }, {
      "category" : "external",
      "summary" : "Juniper Security Bulletin: Junos OS: SRX Series: If VPN compliance-check is configured an attacker can cause http-gk process crash (CVE-2026-57021) vom 2026-07-08",
      "url" : "https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos-OS-SRX-Series-If-VPN-compliance-check-is-configured-an-attacker-can-cause-http-gk-process-crash-CVE-2026-57021"
    } ],
    "source_lang" : "en-US",
    "title" : "Juniper JUNOS und JUNOS Evolved: Mehrere Schwachstellen",
    "tracking" : {
      "current_release_date" : "2026-07-09T22:00:00.000+00:00",
      "generator" : {
        "date" : "2026-07-16T17:41:38.337+00:00",
        "engine" : {
          "name" : "BSI-WID",
          "version" : "1.6.0"
        }
      },
      "id" : "WID-SEC-W-2026-2257",
      "initial_release_date" : "2026-07-08T22:00:00.000+00:00",
      "revision_history" : [ {
        "date" : "2026-07-08T22:00:00.000+00:00",
        "number" : "1",
        "summary" : "Initiale Fassung"
      }, {
        "date" : "2026-07-09T22:00:00.000+00:00",
        "number" : "2",
        "summary" : "Referenz(en) aufgenommen: EUVD-2026-42719, EUVD-2026-42718, EUVD-2026-42716, EUVD-2026-42715, EUVD-2026-42714, EUVD-2026-42713, EUVD-2026-42711, EUVD-2026-42709, EUVD-2026-42708, EUVD-2026-42707, EUVD-2026-42706, EUVD-2026-42704, EUVD-2026-42703, EUVD-2026-42702, EUVD-2026-42700, EUVD-2026-42699, EUVD-2026-42697, EUVD-2026-42712, EUVD-2026-42721, EUVD-2026-42701, EUVD-2026-42724, EUVD-2026-42723"
      } ],
      "status" : "final",
      "version" : "2"
    }
  },
  "product_tree" : {
    "branches" : [ {
      "branches" : [ {
        "category" : "product_name",
        "name" : "Juniper EX Series",
        "product" : {
          "name" : "Juniper EX Series",
          "product_id" : "T019811",
          "product_identification_helper" : {
            "cpe" : "cpe:/h:juniper:ex:-"
          }
        }
      }, {
        "branches" : [ {
          "category" : "product_name",
          "name" : "Juniper JUNOS",
          "product" : {
            "name" : "Juniper JUNOS",
            "product_id" : "5930",
            "product_identification_helper" : {
              "cpe" : "cpe:/o:juniper:junos:-"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Evolved",
          "product" : {
            "name" : "Juniper JUNOS Evolved",
            "product_id" : "T018886",
            "product_identification_helper" : {
              "cpe" : "cpe:/o:juniper:junos:evolved"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "JUNOS"
      }, {
        "category" : "product_name",
        "name" : "Juniper MX Series",
        "product" : {
          "name" : "Juniper MX Series",
          "product_id" : "T052568",
          "product_identification_helper" : {
            "cpe" : "cpe:/h:juniper:mx:-"
          }
        }
      }, {
        "category" : "product_name",
        "name" : "Juniper QFX Series",
        "product" : {
          "name" : "Juniper QFX Series",
          "product_id" : "T019810",
          "product_identification_helper" : {
            "cpe" : "cpe:/h:juniper:qfx:-"
          }
        }
      }, {
        "category" : "product_name",
        "name" : "Juniper SRX Series",
        "product" : {
          "name" : "Juniper SRX Series",
          "product_id" : "T025821",
          "product_identification_helper" : {
            "cpe" : "cpe:/h:juniper:srx_service_gateways:-"
          }
        }
      } ],
      "category" : "vendor",
      "name" : "Juniper"
    } ]
  },
  "vulnerabilities" : [ {
    "cve" : "CVE-2020-7450",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2020-7450"
  }, {
    "cve" : "CVE-2026-21901",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-21901"
  }, {
    "cve" : "CVE-2026-33794",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-33794"
  }, {
    "cve" : "CVE-2026-33799",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-33799"
  }, {
    "cve" : "CVE-2026-33800",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-33800"
  }, {
    "cve" : "CVE-2026-33801",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-33801"
  }, {
    "cve" : "CVE-2026-33802",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-33802"
  }, {
    "cve" : "CVE-2026-33803",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-33803"
  }, {
    "cve" : "CVE-2026-57019",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57019"
  }, {
    "cve" : "CVE-2026-57020",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57020"
  }, {
    "cve" : "CVE-2026-57021",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57021"
  }, {
    "cve" : "CVE-2026-57022",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57022"
  }, {
    "cve" : "CVE-2026-57023",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57023"
  }, {
    "cve" : "CVE-2026-57024",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57024"
  }, {
    "cve" : "CVE-2026-57025",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57025"
  }, {
    "cve" : "CVE-2026-57026",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57026"
  }, {
    "cve" : "CVE-2026-57027",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57027"
  }, {
    "cve" : "CVE-2026-57028",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57028"
  }, {
    "cve" : "CVE-2026-57029",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57029"
  }, {
    "cve" : "CVE-2026-57030",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57030"
  }, {
    "cve" : "CVE-2026-57031",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57031"
  }, {
    "cve" : "CVE-2026-57032",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57032"
  }, {
    "cve" : "CVE-2026-57054",
    "product_status" : {
      "known_affected" : [ "T019810", "T018886", "T019811", "T025821", "T052568", "5930" ]
    },
    "release_date" : "2026-07-08T22:00:00.000+00:00",
    "title" : "CVE-2026-57054"
  } ]
}