Home

Description

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).When processing a high rate of specific GRE traffic destined to the device, the respective PFE will hang causing traffic forwarding to stop. When this issue occurs the following logs can be observed: <fpc #> MQSS(0): LI-3: Received a parcel with more than 512B accompanying data CHASSISD_FPC_ASIC_ERROR: ASIC Error detected <...> This issue affects Junos OS: * all versions before 21.2R3-S9, * 21.4 versions before 21.4R3-S8, * 22.2 versions before 22.2R3-S4, * 22.4 versions before 22.4R3-S5, * 23.2 versions before 23.2R2-S2, * 23.4 versions before 23.4R2.

PUBLISHED Reserved 2025-03-24 | Published 2025-04-09 | Updated 2025-04-09 | Assigner juniper




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/RE:M

Problem types

CWE-754 Improper Check for Unusual or Exceptional Conditions

Product status

Default status
unaffected

Any version before 21.2R3-S9
affected

21.4 (semver) before 21.4R3-S8
affected

22.2 (semver) before 22.2R3-S4
affected

22.4 (semver) before 22.4R3-S5
affected

23.2 (semver) before 23.2R2-S2
affected

23.4 (semver) before 23.4R2
affected

Timeline

2025-04-09:Initial Publication

References

supportportal.juniper.net/JSA96471 vendor-advisory

cve.org (CVE-2025-30660)

nvd.nist.gov (CVE-2025-30660)

Download JSON