📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Technology and Artificial Intelligence MEDIUM 1h Global general Technology and Artificial Intelligence HIGH 2h Global vulnerability Higher Education CRITICAL 11h Global data_breach Government HIGH 12h Global supply_chain Software Development and Open Source Communities CRITICAL 12h Global malware Software Development CRITICAL 12h Global phishing Multiple Sectors HIGH 13h Global vulnerability Web Applications CRITICAL 13h Global apt Critical Infrastructure CRITICAL 13h Global ransomware Multiple sectors CRITICAL 14h Global general Technology and Artificial Intelligence MEDIUM 1h Global general Technology and Artificial Intelligence HIGH 2h Global vulnerability Higher Education CRITICAL 11h Global data_breach Government HIGH 12h Global supply_chain Software Development and Open Source Communities CRITICAL 12h Global malware Software Development CRITICAL 12h Global phishing Multiple Sectors HIGH 13h Global vulnerability Web Applications CRITICAL 13h Global apt Critical Infrastructure CRITICAL 13h Global ransomware Multiple sectors CRITICAL 14h Global general Technology and Artificial Intelligence MEDIUM 1h Global general Technology and Artificial Intelligence HIGH 2h Global vulnerability Higher Education CRITICAL 11h Global data_breach Government HIGH 12h Global supply_chain Software Development and Open Source Communities CRITICAL 12h Global malware Software Development CRITICAL 12h Global phishing Multiple Sectors HIGH 13h Global vulnerability Web Applications CRITICAL 13h Global apt Critical Infrastructure CRITICAL 13h Global ransomware Multiple sectors CRITICAL 14h
Vulnerabilities

CVE-2026-33790

High
CWE-754 — Weakness Type
Published: Apr 9, 2026  ·  Modified: Apr 16, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker sending a specific, malformed ICMPv6 packet to cause the srxpfe process to crash and restart. Continued receipt and processing of these packets will repeatedly crash the srxpfe process and sustain the Denial of Service (DoS) condition.

During NAT64 translation, receipt of a specific, malformed ICMPv6 packet destined to the device will cause the srxpfe process to crash and restart.

This issue cannot be triggered using IPv4 nor other IPv6 traffic.



This issue affects Junos OS on SRX Series:
* all versions before 21.2R3-S10,
* all versions of 21.3,
* from 21.4 before 21.4R3-S12,
* all versions of 22.1,
* from 22.2 before 22.2R3-S8,
* all versions of 22.4,
* from 22.4 before 22.4R3-S9,
* from 23.2 before 23.2R2-S6,
* from 23.4 before 23.4R2-S7,
* from 24.2 before 24.2R2-S3,
* from 24.4 before 24.4R2-S3,
* from 25.2 before 25.2R1-S2, 25.2R2.

🤖 AI Executive Summary

A Denial of Service vulnerability in Juniper Networks Junos OS SRX Series allows attackers to crash the srxpfe process by sending malformed ICMPv6 packets during NAT64 translation. Repeated exploitation sustains service disruption. This affects multiple Junos OS versions with no patch currently available, requiring immediate compensating controls for organizations operating SRX firewalls in production environments.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 3, 2026 10:49
🇸🇦 Saudi Arabia Impact Assessment
Critical impact for Saudi organizations operating Juniper SRX firewalls as perimeter security devices. Primary affected sectors: (1) Banking & Financial Services (SAMA-regulated institutions) — SRX devices protect critical payment infrastructure and SWIFT connections; (2) Government & Critical Infrastructure (NCA oversight) — SRX firewalls secure government networks and national security systems; (3) Energy Sector (ARAMCO, utilities) — SRX devices protect SCADA/ICS networks; (4) Telecommunications (STC, Mobily, Zain) — SRX firewalls manage carrier-grade traffic. The NAT64-specific trigger is particularly relevant for Saudi organizations transitioning to IPv6 or operating dual-stack environments. Sustained DoS could disrupt critical services, financial transactions, and government operations.
🏢 Affected Saudi Sectors
Banking & Financial Services Government & Public Administration Energy & Utilities Telecommunications Healthcare Critical Infrastructure
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all SRX Series devices in your network and document their current Junos OS versions
2. Disable NAT64 translation if not operationally required — this eliminates the attack vector
3. Implement ICMPv6 filtering at network perimeter to block malformed ICMPv6 packets destined to SRX devices
4. Deploy rate-limiting on ICMPv6 traffic to reduce DoS impact

PATCHING GUIDANCE:
1. Monitor Juniper security advisories for patch releases matching your version (21.2R3-S10+, 21.4R3-S12+, 22.2R3-S8+, 22.4R3-S9+, 23.2R2-S6+, 23.4R2-S7+, 24.2R2-S3+, 24.4R2-S3+, 25.2R1-S2+)
2. Plan upgrade to patched version during maintenance window
3. Test patches in lab environment before production deployment

COMPENSATING CONTROLS (until patch available):
1. Configure access-lists to deny ICMPv6 type 0-127 (informational messages) if not required
2. Implement stateful firewall rules limiting ICMPv6 echo requests
3. Monitor srxpfe process restarts using syslog alerts
4. Configure automatic failover to secondary SRX if available
5. Implement network segmentation to limit exposure of NAT64-enabled interfaces

DETECTION RULES:
1. Alert on srxpfe process crashes/restarts (check system logs for 'srxpfe' restart events)
2. Monitor for unusual ICMPv6 traffic patterns destined to SRX management/data interfaces
3. Track ICMPv6 packet anomalies (malformed headers, invalid checksums)
4. Correlate ICMPv6 traffic spikes with srxpfe restart events
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حدد جميع أجهزة SRX Series في شبكتك وقثق إصدارات Junos OS الحالية
2. عطّل ترجمة NAT64 إذا لم تكن مطلوبة تشغيلياً — هذا يلغي متجه الهجوم
3. طبّق تصفية ICMPv6 على محيط الشبكة لحجب حزم ICMPv6 المشوهة الموجهة لأجهزة SRX
4. طبّق تحديد معدل على حركة ICMPv6 لتقليل تأثير حجب الخدمة

إرشادات التصحيح:
1. راقب إشعارات أمان Juniper للحصول على إصدارات التصحيح المطابقة لإصدارك
2. خطط للترقية إلى إصدار مصحح أثناء نافذة الصيانة
3. اختبر التصحيحات في بيئة المختبر قبل نشرها في الإنتاج

الضوابط التعويضية (حتى توفر التصحيح):
1. كوّن قوائم التحكم في الوصول لرفض نوع ICMPv6 0-127 إذا لم تكن مطلوبة
2. طبّق قواعد جدار الحماية الحالة لتحديد طلبات صدى ICMPv6
3. راقب إعادة تشغيل عملية srxpfe باستخدام تنبيهات syslog
4. كوّن الفشل التلقائي إلى SRX ثانوي إذا كان متاحاً
5. طبّق تقسيم الشبكة لتحديد تعريض الواجهات المفعلة NAT64

قواعد الكشف:
1. تنبيه عند توقف/إعادة تشغيل عملية srxpfe (تحقق من سجلات النظام)
2. راقب أنماط حركة ICMPv6 غير العادية الموجهة لواجهات إدارة/بيانات SRX
3. تتبع شذوذ حزم ICMPv6 (رؤوس مشوهة، مجاميع اختيار غير صحيحة)
4. ربط طفرات حركة ICMPv6 مع أحداث إعادة تشغيل srxpfe
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 — Management of technical vulnerabilities (patch management) ECC 2024 A.13.1.1 — Network security perimeter controls (firewall configuration) ECC 2024 A.13.1.3 — Segregation of networks (network segmentation) ECC 2024 A.14.2.1 — Change management procedures (SRX configuration changes)
🔵 SAMA CSF
SAMA CSF ID.RA-1 — Asset management and vulnerability identification SAMA CSF PR.IP-12 — Security patch management SAMA CSF DE.CM-1 — Detection and analysis of anomalies SAMA CSF RS.MI-1 — Incident response and mitigation
🟡 ISO 27001:2022
ISO 27001:2022 A.12.3.1 — Patch management procedures ISO 27001:2022 A.13.1.1 — Network security architecture ISO 27001:2022 A.13.1.3 — Network segregation ISO 27001:2022 A.8.1.1 — Inventory of information assets
🟣 PCI DSS v4.0.1
PCI DSS 6.2 — Security patch management PCI DSS 1.1 — Firewall configuration standards PCI DSS 1.3 — Network segmentation
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-754
EPSS0.04%
Exploit No
Patch ✗ No
Published 2026-04-09
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-754
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.