CVE-2026-57032: Junos OS: EX Series: Subscribing to an unsupported telemetry sensor path causes fxpc process crash
An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low privileges to cause a Denial-of-Service (DoS).
If an attempt is made to subscribe to an unsupported telemetry sensor path on EX2300, EX3400, EX4000, EX4100 and EX4400 via gRPC, this causes the FPC to crash. This leads to a complete service outage until the module has automatically restarted.
The following log message can be seen when this issue happens:
agentd[<PID>]: AGENTDRESOURCENOTFOUND: No resource name found for <sensor>
This issue affects Junos OS on
EX2300, EX3400, EX4000, EX4100 and EX4400
devices:
all versions before 23.2R2-S7, 23.4 versions before 23.4R2-S8, 24.2 versions before 24.2R2-S5, 24.4 versions before 24.4R2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos OS (EX Series pfe/telemetry on EX2300, EX3400, EX4000, EX4100, EX4400)to a version that resolves this vulnerability.Fixed in 23.2R2-S7 - Upgrade
Upgrade
Juniper Networks Junos OS (EX Series pfe/telemetry on EX2300, EX3400, EX4000, EX4100, EX4400)to a version that resolves this vulnerability.Fixed in 23.4R2-S8 - Upgrade
Upgrade
Juniper Networks Junos OS (EX Series pfe/telemetry on EX2300, EX3400, EX4000, EX4100, EX4400)to a version that resolves this vulnerability.Fixed in 24.2R2-S5 - Upgrade
Upgrade
Juniper Networks Junos OS (EX Series pfe/telemetry on EX2300, EX3400, EX4000, EX4100, EX4400)to a version that resolves this vulnerability.Fixed in 24.4R2 - Upgrade
Upgrade
Juniper Networks Junos OS (EX Series pfe/telemetry on EX2300, EX3400, EX4000, EX4100, EX4400)to a version that resolves this vulnerability.Fixed in 25.2R1 - Compensating control
Avoid subscribing via gRPC to unsupported telemetry sensor paths on EX2300, EX3400, EX4000, EX4100, and EX4400 (this can trigger an FPC crash and complete service outage until the module restarts).
- Operational
If the issue is triggered and the fxpc/agentd-related modules crash and restart, verify service availability and monitor for AGENTD_RESOURCE_NOT_FOUND log entries indicating unsupported telemetry sensor path subscription attempts (e.g., agentd[<PID>]: AGENTD_RESOURCE_NOT_FOUND: No resource name found for <sensor>).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57032?
The severity of CVE-2026-57032 is medium with a score of 6.5.
How do I fix CVE-2026-57032?
To fix CVE-2026-57032, ensure that you are not subscribing to unsupported telemetry sensor paths on Junos OS EX Series devices.
What impact does CVE-2026-57032 have on my system?
CVE-2026-57032 allows an authenticated attacker to cause a Denial-of-Service (DoS) by leading to a crash of the fxpc process.
Who is affected by CVE-2026-57032?
CVE-2026-57032 affects devices running Juniper Networks Junos OS on EX Series that allow subscription to telemetry sensors.
What conditions are required to exploit CVE-2026-57032?
An attacker must have authenticated low privileges and attempt to subscribe to an unsupported telemetry sensor path to exploit CVE-2026-57032.