📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global apt Government and Defense CRITICAL 39m Global general Technology / Consumer Protection MEDIUM 50m Global vulnerability Information Technology and Security CRITICAL 58m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 2h Global vulnerability Information Technology and Infrastructure HIGH 3h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 39m Global general Technology / Consumer Protection MEDIUM 50m Global vulnerability Information Technology and Security CRITICAL 58m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 2h Global vulnerability Information Technology and Infrastructure HIGH 3h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 39m Global general Technology / Consumer Protection MEDIUM 50m Global vulnerability Information Technology and Security CRITICAL 58m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 2h Global vulnerability Information Technology and Infrastructure HIGH 3h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h
Vulnerabilities

CVE-2026-33773

Medium
Published: Apr 9, 2026  ·  Modified: Apr 12, 2026  ·  Source: NVD
CVSS v3
5.8
🔗 NVD Official
📄 Description (English)

An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device allows an unauthenticated, network-based attacker to cause an integrity impact to downstream networks.

When the same family inet or inet6 filter is applied on an IRB interface and on a physical interface as egress filter on EX4100, EX4400, EX4650 and QFX5120 devices, only one of the two filters will be applied, which can lead to traffic being sent out one of these interfaces which should have been blocked.

This issue affects Junos OS on EX Series and QFX Series:
* 23.4 version 23.4R2-S6,
* 24.2 version 24.2R2-S3.


No other Junos OS versions are affected.

🤖 AI Executive Summary

A critical filter bypass vulnerability in Juniper Junos OS affects EX and QFX series switches used in Saudi networks. When identical firewall filters are applied to both IRB and physical interfaces, only one filter is enforced, allowing unauthorized traffic to bypass security controls. This integrity impact poses significant risk to network segmentation and data protection in Saudi organizations relying on these devices for perimeter and internal security.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 24, 2026 19:01
🇸🇦 Saudi Arabia Impact Assessment
High impact for Saudi banking sector (SAMA-regulated institutions) using Juniper EX/QFX switches for network segmentation and DLP enforcement. Government agencies (NCA oversight) face integrity risks in classified network isolation. Telecom operators (STC, Mobily, Zain) managing core network infrastructure are vulnerable to traffic leakage. Energy sector (ARAMCO, SEC) relying on these switches for OT/IT separation faces operational technology exposure. Healthcare institutions using these devices for patient data isolation are at compliance risk. The vulnerability directly undermines network access control policies critical to Saudi cybersecurity frameworks.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Telecommunications Energy and Utilities Healthcare Critical Infrastructure
⚖️ Saudi Risk Score (AI)
7.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Audit all EX4100, EX4400, EX4650, and QFX5120 devices running Junos OS 23.4R2-S6 or 24.2R2-S3
2. Verify filter configurations on IRB and physical interfaces to identify dual-filter deployments
3. Implement compensating controls: consolidate filters to single interface point or use alternative filtering mechanisms
4. Enable enhanced logging on affected interfaces to detect unauthorized traffic egress

COMPENSATING CONTROLS (until patch available):
- Apply filters only to physical interfaces, remove from IRB interfaces temporarily
- Implement additional filtering at upstream/downstream devices
- Deploy NetFlow/sFlow monitoring to detect anomalous traffic patterns
- Use VLAN-based access controls as secondary enforcement

DETECTION:
- Monitor for traffic on interfaces that should be blocked by filters
- Alert on filter configuration mismatches between IRB and physical interfaces
- Track Junos OS version inventory for affected releases
- Implement IDS/IPS rules to detect traffic that violates expected filter policies

PATCHING:
- Contact Juniper for patch availability timeline
- Plan upgrade to non-affected Junos OS versions when patches released
- Test patches in lab environment before production deployment
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تدقيق جميع أجهزة EX4100 و EX4400 و EX4650 و QFX5120 التي تعمل بنظام Junos OS 23.4R2-S6 أو 24.2R2-S3
2. التحقق من تكوينات المرشحات على واجهات IRB والواجهات الفيزيائية لتحديد نشرات المرشحات المزدوجة
3. تطبيق عناصر التحكم التعويضية: دمج المرشحات في نقطة واجهة واحدة أو استخدام آليات تصفية بديلة
4. تفعيل السجلات المحسنة على الواجهات المتأثرة للكشف عن خروج حركة المرور غير المصرح بها

عناصر التحكم التعويضية (حتى توفر التصحيح):
- تطبيق المرشحات على الواجهات الفيزيائية فقط، إزالتها من واجهات IRB مؤقتاً
- تطبيق تصفية إضافية على الأجهزة العلوية/السفلية
- نشر مراقبة NetFlow/sFlow للكشف عن أنماط حركة المرور الشاذة
- استخدام عناصر التحكم في الوصول القائمة على VLAN كإنفاذ ثانوي

الكشف:
- مراقبة حركة المرور على الواجهات التي يجب حظرها بواسطة المرشحات
- تنبيهات عدم تطابق تكوين المرشحات بين واجهات IRB والواجهات الفيزيائية
- تتبع جرد إصدار Junos OS للإصدارات المتأثرة
- تطبيق قواعد IDS/IPS للكشف عن حركة المرور التي تنتهك سياسات المرشحات المتوقعة

التصحيح:
- الاتصال بـ Juniper للحصول على جدول زمني لتوفر التصحيح
- التخطيط للترقية إلى إصدارات Junos OS غير المتأثرة عند إصدار التصحيحات
- اختبار التصحيحات في بيئة المختبر قبل نشرها في الإنتاج
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.13.1.1 - Network access control and segregation ECC 2024 A.13.1.3 - Segregation of networks ECC 2024 A.14.2.1 - Secure development policy ECC 2024 A.8.2.3 - Segregation of duties
🔵 SAMA CSF
SAMA CSF ID.BE-1 - Business objectives and strategies SAMA CSF PR.AC-3 - Access control and management SAMA CSF PR.AC-4 - Access rights and privileges SAMA CSF DE.CM-1 - Detection and analysis
🟡 ISO 27001:2022
ISO 27001:2022 A.8.1 - User endpoint devices ISO 27001:2022 A.8.2 - Privileged access rights ISO 27001:2022 A.8.3 - Information access restriction ISO 27001:2022 A.13.1 - Network security perimeter
🟣 PCI DSS v4.0.1
PCI DSS 1.1 - Firewall configuration standards PCI DSS 1.2 - Firewall and router configuration documentation PCI DSS 1.3 - Network segmentation
📊 CVSS Score
5.8
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeC — Changed
ConfidentialityN — None / Network
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score5.8
EPSS0.04%
Exploit No
Patch ✗ No
Published 2026-04-09
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
7.2
/ 10.0 — Saudi Risk
Priority: HIGH
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.