CVE-2025-60003
7.5Juniper Networks · Junos OS and Junos OS Evolved
A buffer over-read vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network attacker to cause a denial of service.
Executive summary
An unauthenticated remote attacker can trigger a crash and restart of the routing protocol daemon in Juniper Networks Junos OS and Junos OS Evolved by sending specific BGP updates, causing a Denial of Service.
Vulnerability
This vulnerability is a buffer over-read (CWE-126) located in the routing protocol daemon (rpd). It is triggered when an unauthenticated attacker sends a BGP update containing specific optional transitive attributes to a device, provided the session involves a non-4-byte-AS capable peer.
Business impact
The exploitation of this vulnerability results in a critical Denial of Service (DoS) condition, as the routing protocol daemon will crash and restart upon receiving malicious BGP traffic. This leads to the disruption of network routing services, potentially causing significant downtime for connected infrastructure. With a CVSS score of 7.5, this issue presents a high risk to operational continuity, especially for core network appliances.
Remediation
Immediate Action: Upgrade to the patched software releases provided by Juniper Networks, specifically 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S2, 24.4R2, 25.2R1, or their corresponding Evolved versions.
Proactive Monitoring: Monitor system logs for repeated rpd process crashes and review BGP peering sessions to identify peers that are not 4-byte-AS capable.
Compensating Controls: If patching is not immediately feasible, verify if the 4-byte-AS capability can be managed or restricted for untrusted peering sessions to mitigate the attack vector.
Exploitation status
Public Exploit Available: No — exploit_available (false).
Analyst recommendation
Given the potential for widespread network instability, organizations should prioritize the deployment of the vendor-supplied patches across all affected Juniper network infrastructure. Regular maintenance cycles should be accelerated to address this vulnerability, as the lack of authentication requirements makes it an attractive target for network-based attackers.
More Juniper Networks CVEs
Sources
Originally found and disclosed by Juniper SIRT would like to acknowledge and thank Craig Dods from Meta’s Infrastructure Security Engineering team for res, per the CVE Program record.