When TCP proxy is engaged in a flow session, to support ALGs, Advanced Anti-Malware, ICAP or UTM, a TCP packet with specifically malformed TCP header will cause flow processing daemon (flowd) to crash and restart. This causes a complete service outage until the system has automatically recovered.
This issue affects Junos OS on MX with SPC3, and SRX Series:
* 23.4 versions before 23.4R2-S7,
* 24.2 versions before 24.2R2-S4,
* 24.4 versions before 24.4R2-S3,
* 25.2 versions before 25.2R2.
This issue does not affect releases before 23.4R1.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Juniper
Subscribe
|
Junos
Subscribe
Mx-spc3
Subscribe
Mx240
Subscribe
Mx480
Subscribe
Mx960
Subscribe
Srx1500
Subscribe
Srx1600
Subscribe
Srx2300
Subscribe
Srx300
Subscribe
Srx320
Subscribe
Srx340
Subscribe
Srx345
Subscribe
Srx380
Subscribe
Srx400
Subscribe
Srx4100
Subscribe
Srx4120
Subscribe
Srx4200
Subscribe
Srx4300
Subscribe
Srx440
Subscribe
Srx4600
Subscribe
Srx4700
Subscribe
Srx5400
Subscribe
Srx5600
Subscribe
Srx5800
Subscribe
|
|
Juniper Networks
Subscribe
|
Junos Os
Subscribe
|
No advisories yet.
Solution
The following software releases have been updated to resolve this specific issue: 23.4R2-S7, 24.2R2-S4, 24.4R2-S3, 25.2R2, 25.4R1, and all subsequent releases.
Workaround
There are no known workarounds for this issue.
| Link | Providers |
|---|---|
| https://supportportal.juniper.net/JSA110083 |
|
Fri, 10 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Juniper Networks
Juniper Networks junos Os |
|
| Vendors & Products |
Juniper Networks
Juniper Networks junos Os |
Thu, 09 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS). When TCP proxy is engaged in a flow session, to support ALGs, Advanced Anti-Malware, ICAP or UTM, a TCP packet with specifically malformed TCP header will cause flow processing daemon (flowd) to crash and restart. This causes a complete service outage until the system has automatically recovered. This issue affects Junos OS on MX with SPC3, and SRX Series: * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R2. This issue does not affect releases before 23.4R1. | |
| Title | Junos OS: MX with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd crash | |
| Weaknesses | CWE-1284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: juniper
Published:
Updated: 2026-07-10T15:28:45.274Z
Reserved: 2026-06-23T16:27:00.248Z
Link: CVE-2026-57023
Updated: 2026-07-10T15:28:41.871Z
Status : Analyzed
Published: 2026-07-09T22:17:07.397
Modified: 2026-07-14T15:19:42.860
Link: CVE-2026-57023
No data.
OpenCVE Enrichment
Updated: 2026-08-03T04:30:18Z