CVE-2026-33786: Junos OS: SRX1600, SRX2300, SRX4300: When a specific show command is executed chassisd crashes
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS).
When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts which causes a momentary impact to all traffic until all modules are online again.
This issue affects Junos OS on SRX1600, SRX2300 and SRX4300:
24.4 versions before 24.4R1-S3, 24.4R2.
This issue does not affect Junos OS versions before 24.4R1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33786?
The severity of CVE-2026-33786 is classified as high due to the potential for local attackers to exploit the vulnerability.
How do I fix CVE-2026-33786?
To fix CVE-2026-33786, it is recommended to upgrade the Junos OS to version 24.4R2 or a version above 24.4R1-S3.
Who is affected by CVE-2026-33786?
CVE-2026-33786 affects Juniper Networks Junos OS on specific models, including SRX1600, SRX2300, and SRX4300.
What type of vulnerability is CVE-2026-33786?
CVE-2026-33786 is an Improper Check for Unusual or Exceptional Conditions vulnerability within the chassis control daemon of Junos OS.
Can CVE-2026-33786 be exploited remotely?
No, CVE-2026-33786 requires local access for exploitation, as the attacker must execute a specific show command.