📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Higher Education CRITICAL 9h Global data_breach Government HIGH 10h Global supply_chain Software Development and Open Source Communities CRITICAL 10h Global malware Software Development CRITICAL 10h Global phishing Multiple Sectors HIGH 10h Global vulnerability Web Applications CRITICAL 11h Global apt Critical Infrastructure CRITICAL 11h Global ransomware Multiple sectors CRITICAL 12h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 12h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 13h Global vulnerability Higher Education CRITICAL 9h Global data_breach Government HIGH 10h Global supply_chain Software Development and Open Source Communities CRITICAL 10h Global malware Software Development CRITICAL 10h Global phishing Multiple Sectors HIGH 10h Global vulnerability Web Applications CRITICAL 11h Global apt Critical Infrastructure CRITICAL 11h Global ransomware Multiple sectors CRITICAL 12h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 12h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 13h Global vulnerability Higher Education CRITICAL 9h Global data_breach Government HIGH 10h Global supply_chain Software Development and Open Source Communities CRITICAL 10h Global malware Software Development CRITICAL 10h Global phishing Multiple Sectors HIGH 10h Global vulnerability Web Applications CRITICAL 11h Global apt Critical Infrastructure CRITICAL 11h Global ransomware Multiple sectors CRITICAL 12h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 12h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 13h
Vulnerabilities

CVE-2026-33797

High
CWE-20 — Weakness Type
Published: Apr 9, 2026  ·  Modified: Apr 16, 2026  ·  Source: NVD
CVSS v3
7.4
🔗 NVD Official
📄 Description (English)

An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS).

An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS:

* 25.2 versions before 25.2R2


This issue doesn't not affected Junos OS versions before 25.2R1.

This issue affects Junos OS Evolved:
* 25.2-EVO versions before 25.2R2-EVO


This issue doesn't not affected Junos OS Evolved versions before 25.2R1-EVO.

eBGP and iBGP are affected.
IPv4 and IPv6 are affected.

🤖 AI Executive Summary

CVE-2026-33797 is a high-severity input validation flaw in Juniper Junos OS 25.2 and Junos OS Evolved 25.2 that allows unauthenticated adjacent attackers to trigger BGP session resets via malformed BGP packets, causing sustained denial of service. The vulnerability affects both eBGP and iBGP sessions over IPv4 and IPv6, impacting critical network infrastructure. No patch is currently available, requiring immediate compensating controls for affected Saudi organizations.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 4, 2026 19:54
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses critical risk to Saudi telecommunications infrastructure (STC, Mobily, Zain), ARAMCO's energy networks, SAMA-regulated banking sector, and government networks (NCA, NCSC). BGP is fundamental to internet routing; sustained DoS attacks could fragment network connectivity across critical sectors. Organizations running Juniper equipment in border gateway or core routing positions face immediate service disruption risk. The adjacent-network requirement limits exposure but is feasible in data center, ISP, and enterprise environments prevalent in Saudi Arabia.
🏢 Affected Saudi Sectors
Telecommunications (STC, Mobily, Zain) Energy (ARAMCO, power utilities) Banking and Financial Services (SAMA-regulated) Government (NCA, NCSC, ministries) Healthcare Data Centers and Cloud Providers ISPs and Network Service Providers
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all Juniper Junos OS 25.2 and Junos OS Evolved 25.2 deployments in your network using inventory management tools
2. Isolate affected devices from untrusted adjacent networks where possible
3. Implement strict BGP session authentication using MD5 or TCP-AO to prevent unauthorized packet injection
4. Enable BGP session monitoring and alerting for unexpected resets

COMPENSATING CONTROLS (until patch available):
5. Deploy BGP packet filtering at network edges to validate BGP packet structure before reaching routers
6. Implement rate limiting on BGP packets from adjacent peers
7. Configure BGP graceful restart to minimize impact of session resets
8. Establish redundant BGP sessions with diverse paths to critical peers
9. Monitor syslog for BGP session state changes and correlate with traffic anomalies

DETECTION RULES:
10. Alert on BGP session resets from specific adjacent peers within short time windows (e.g., >3 resets in 5 minutes)
11. Monitor for malformed BGP UPDATE messages using packet inspection
12. Track BGP session uptime metrics and flag abnormal patterns
13. Correlate BGP resets with network performance degradation

PATCHING STRATEGY:
14. Monitor Juniper security advisories for patch release (expected for 25.2R2 and 25.2R2-EVO)
15. Plan immediate patching upon availability; test in lab environment first
16. Consider downgrading to pre-25.2R1 versions if critical and patch unavailable
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حدد جميع نشرات Juniper Junos OS 25.2 و Junos OS Evolved 25.2 في شبكتك باستخدام أدوات إدارة المخزون
2. عزل الأجهزة المتأثرة عن الشبكات المجاورة غير الموثوقة حيث أمكن
3. تطبيق مصادقة جلسة BGP الصارمة باستخدام MD5 أو TCP-AO لمنع حقن الحزم غير المصرح بها
4. تفعيل مراقبة جلسة BGP والتنبيهات لإعادة التعيين غير المتوقعة

الضوابط التعويضية (حتى توفر التصحيح):
5. نشر تصفية حزم BGP على حواف الشبكة للتحقق من صحة هيكل حزم BGP قبل وصولها إلى الموجهات
6. تطبيق تحديد معدل على حزم BGP من نظراء مجاورين
7. تكوين إعادة تشغيل BGP الرشيقة لتقليل تأثير إعادة تعيين الجلسة
8. إنشاء جلسات BGP زائدة عن الحاجة مع مسارات متنوعة للنظراء الحرجين
9. مراقبة syslog لتغييرات حالة جلسة BGP والربط مع شذوذ حركة المرور

قواعد الكشف:
10. تنبيه عند إعادة تعيين جلسة BGP من نظراء مجاورين محددين ضمن نوافذ زمنية قصيرة (مثل >3 إعادة تعيين في 5 دقائق)
11. مراقبة رسائل BGP UPDATE المشوهة باستخدام فحص الحزم
12. تتبع مقاييس وقت تشغيل جلسة BGP والإشارة إلى الأنماط غير الطبيعية
13. ربط إعادة تعيين BGP مع تدهور أداء الشبكة

استراتيجية التصحيح:
14. مراقبة نشرات أمان Juniper لإصدار التصحيح (متوقع لـ 25.2R2 و 25.2R2-EVO)
15. خطط التصحيح الفوري عند التوفر؛ اختبر في بيئة المختبر أولاً
16. فكر في الرجوع إلى الإصدارات السابقة لـ 25.2R1 إذا كانت حرجة والتصحيح غير متاح
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.12.2.1 - Change management procedures ECC 2024 A.13.1.1 - Network security perimeter ECC 2024 A.13.2.1 - Segregation of networks
🔵 SAMA CSF
SAMA CSF ID.BE-1 - Business objectives and strategies SAMA CSF PR.IP-12 - Information and records management SAMA CSF DE.CM-1 - Detection processes and tools SAMA CSF RS.MI-1 - Incident response procedures
🟡 ISO 27001:2022
ISO 27001:2022 A.12.2.1 - Change management ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities ISO 27001:2022 A.13.1.1 - Network security perimeter ISO 27001:2022 A.14.2.1 - Secure development policy
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Security patches and updates PCI DSS 11.2 - Vulnerability scanning
📊 CVSS Score
7.4
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack VectorA — Adjacent
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeC — Changed
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.4
CWECWE-20
EPSS0.02%
Exploit No
Patch ✗ No
Published 2026-04-09
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-20
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.