CVE-2026-33786
published 2026-04-09CVE-2026-33786: An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.10%
0.8th percentile
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS).
When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts which causes a momentary impact to all traffic until all modules are online again.
This issue affects Junos OS on SRX1600, SRX2300 and SRX4300:
* 24.4 versions before 24.4R1-S3, 24.4R2.
This issue does not affect Junos OS versions before 24.4R1.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper | srx_series | — | — |
| juniper_networks | junos_os | >= 24.4 < 24.4R1-S3, 24.4R2 | 24.4R1-S3, 24.4R2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Juniper
CVE-2026-33786: An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600
vendor_juniper·2026-04-09·CVSS 5.5
CVE-2026-33786 [MEDIUM] CWE-754 CVE-2026-33786: An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600
CVE-2026-33786: An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS).
When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts which causes a momentary impact to all traffic until all modules are online again.
This issue affects Junos OS on SRX1600, SRX2300 and SRX4300:
* 24.4 versions before 24.4R1-S3, 24.4R2.
This issue does not affect Junos OS versions before 24.4R1.
VulDB
Juniper Junos OS up to 24.4R1-S3/24.4R1 CLI Command unusual condition (JSA107810)
vuldb·2026-04-10·CVSS 6.8
CVE-2026-33786 [MEDIUM] Juniper Junos OS up to 24.4R1-S3/24.4R1 CLI Command unusual condition (JSA107810)
A vulnerability was found in Juniper Junos OS up to 24.4R1-S3/24.4R1. It has been declared as problematic. Affected is an unknown function of the component CLI Command Handler. Executing a manipulation can lead to improper check for unusual conditions.
This vulnerability is registered as CVE-2026-33786. The attack needs to be launched locally. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
GHSA-xh4h-63x5-gr2f: An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600
ghsa_unreviewed·2026-04-10
CVE-2026-33786 [MEDIUM] CWE-754 GHSA-xh4h-63x5-gr2f: An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS).
When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts which causes a momentary impact to all traffic until all modules are online again.
This issue affects Junos OS on SRX1600, SRX2300 and SRX4300:
* 24.4 versions before 24.4R1-S3, 24.4R2.
This issue does not affect Junos OS versions before 24.4R1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-09
Published