CVE Feed

    Dashboard / CVE / CVE-2026-21913

    CVE-2026-21913

    An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on EX4000 models allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On EX4000 models with 48 ports (EX4000-48T, EX4000-48P, EX4000-48MP) a high volume of traffic destined to the device will cause an FXPC crash and restart, which leads to a complete service outage until the device has automatically restarted. The following reboot reason can be seen in the output of 'show chassis routing-engine' and as a log message:   reason=0x4000002 reason_string=0x4000002:watchdog + panic with core dump This issue affects Junos OS on EX4000-48T, EX4000-48P and EX4000-48MP: * 24.4 versions before 24.4R2, * 25.2 versions before 25.2R1-S2, 25.2R2. This issue does not affect versions before 24.4R1 as the first Junos OS version for the EX4000 models was 24.4R1.

    Published:Jan 15, 2026
    Last Modified:Apr 18, 2026
    EPS:Jan 15, 2026
    EPSS Score:0.00018
    CVSS Score:7.5

    Affected Products

    Vendor
    Juniper
    Product
    Ex4000-48mp
    Vendor
    Juniper
    Product
    Ex4000-48p
    Vendor
    Juniper
    Product
    Ex4000-48t
    Vendor
    Juniper
    Product
    Junos
    Vendor
    Juniper Networks
    Product
    Junos Os

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High