CVE-2025-60003

7.5

Juniper Networks · Junos OS and Junos OS Evolved

A buffer over-read vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network attacker to cause a denial of service.

Executive summary

An unauthenticated remote attacker can trigger a crash and restart of the routing protocol daemon in Juniper Networks Junos OS and Junos OS Evolved by sending specific BGP updates, causing a Denial of Service.

Vulnerability

This vulnerability is a buffer over-read (CWE-126) located in the routing protocol daemon (rpd). It is triggered when an unauthenticated attacker sends a BGP update containing specific optional transitive attributes to a device, provided the session involves a non-4-byte-AS capable peer.

Business impact

The exploitation of this vulnerability results in a critical Denial of Service (DoS) condition, as the routing protocol daemon will crash and restart upon receiving malicious BGP traffic. This leads to the disruption of network routing services, potentially causing significant downtime for connected infrastructure. With a CVSS score of 7.5, this issue presents a high risk to operational continuity, especially for core network appliances.

Remediation

Immediate Action: Upgrade to the patched software releases provided by Juniper Networks, specifically 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S2, 24.4R2, 25.2R1, or their corresponding Evolved versions.

Proactive Monitoring: Monitor system logs for repeated rpd process crashes and review BGP peering sessions to identify peers that are not 4-byte-AS capable.

Compensating Controls: If patching is not immediately feasible, verify if the 4-byte-AS capability can be managed or restricted for untrusted peering sessions to mitigate the attack vector.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

Given the potential for widespread network instability, organizations should prioritize the deployment of the vendor-supplied patches across all affected Juniper network infrastructure. Regular maintenance cycles should be accelerated to address this vulnerability, as the lack of authentication requirements makes it an attractive target for network-based attackers.

More Juniper Networks CVEs

Sources

Originally found and disclosed by Juniper SIRT would like to acknowledge and thank Craig Dods from Meta’s Infrastructure Security Engineering team for res, per the CVE Program record.