{"id":"CVE-2026-33799","title":"An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak","summary":"An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, c…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-787"],"vendor":"juniper","product":"junos","affected":["junos < 21.2","junos = 21.2","junos = 21.4","junos = 22.1","junos = 22.2","junos = 22.3","junos = 22.4","junos = 23.2","junos = 23.4","junos_os_evolved < 21.2","junos_os_evolved = 21.2","junos_os_evolved = 21.4","junos_os_evolved = 22.1","junos_os_evolved = 22.2","junos_os_evolved = 22.3","junos_os_evolved = 22.4","junos_os_evolved = 23.2","junos_os_evolved = 23.4"],"patched":["junos 21.2","junos_os_evolved 21.2"],"published":"2026-07-09","updated":"2026-07-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-33799","references":[{"url":"https://supportportal.juniper.net/JSA110074","label":"sirt@juniper.net"}],"tags":["nvd"],"epss":0.00367,"epssPercentile":0.30446,"ingestedAt":"2026-07-13T13:27:18.420Z","slug":"CVE-2026-33799","body":"## Overview\n\nAn Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion, resulting in a process crash and restart, impacting the ability to monitor the system via SNMP.\n\nMemory usage can be monitored using the following command:\n\nuser@device> show system processes extensive | match snmpd\n\n\n\n\nThis issue affects:\n\nJunos OS:\n\n\n  *  all versions before 21.2R3-S8;\n  *  from 21.4 before 21.4R3-S7;\n  *  from 22.1 before 22.1R3-S6;\n  *  from 22.2 before 22.2R3-S4;\n  *  from 22.3 before 22.3R3-S3;\n  *  from 22.4 before 22.4R3-S2;\n  *  from 23.2 before 23.2R2;\n  *  from 23.4 before 23.4R2.\n\n\n\nJunos OS Evolved:\n  *  all versions before 21.2R3-S8-EVO;\n  *  from 21.4 before 21.4R3-S7-EVO;\n  *  all versions of 22.1-EVO,\n  *  from 22.2 before 22.2R3-S4-EVO;\n  *  from 22.3 before 22.3R3-S3-EVO;\n  *  all versions of 22.4-EVO,\n  *  from 23.2 before 23.2R2-EVO;\n  *  from 23.4 before 23.4R2-EVO.\n\n## Affected\n\n- `junos < 21.2`\n- `junos = 21.2`\n- `junos = 21.4`\n- `junos = 22.1`\n- `junos = 22.2`\n- `junos = 22.3`\n- `junos = 22.4`\n- `junos = 23.2`\n- `junos = 23.4`\n- `junos_os_evolved < 21.2`\n- `junos_os_evolved = 21.2`\n- `junos_os_evolved = 21.4`\n- `junos_os_evolved = 22.1`\n- `junos_os_evolved = 22.2`\n- `junos_os_evolved = 22.3`\n- `junos_os_evolved = 22.4`\n- `junos_os_evolved = 23.2`\n- `junos_os_evolved = 23.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `junos 21.2`\n- `junos_os_evolved 21.2`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}