We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-52958

Junos OS and Junos OS Evolved: When route validation is enabled, BGP connection establishment failure causes RPD crash



Description

A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS).On all Junos OS and Junos OS Evolved devices, when route validation is enabled, a rare condition during BGP initial session establishment can lead to an rpd crash and restart. This occurs specifically when the connection request fails during error-handling scenario. Continued session establishment failures leads to a sustained DoS condition.  This issue affects Junos OS: * All versions before 22.2R3-S6, * from 22.4 before 22.4R3-S6, * from 23.2 before 23.2R2-S3, * from 23.4 before 23.4R2-S4, * from 24.2 before 24.2R2; Junos OS Evolved: * All versions before 22.2R3-S6-EVO, * from 22.4 before 22.4R3-S6-EVO, * from 23.2 before 23.2R2-S3-EVO, * from 23.4 before 23.4R2-S4-EVO, * from 24.2 before 24.2R2-EVO.

Reserved 2025-06-23 | Published 2025-07-11 | Updated 2025-07-11 | Assigner juniper


MEDIUM: 5.3CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

MEDIUM: 6.0CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/R:A/RE:M/U:Green

Problem types

CWE-617 Reachable Assertion

Product status

Default status
unaffected

Any version before 22.2R3-S6
affected

22.4 before 22.4R3-S6
affected

23.2 before 23.2R2-S3
affected

23.4 before 23.4R2-S4
affected

24.2 before 24.2R2
affected

Default status
unaffected

Any version before 22.2R3-S6-EVO
affected

22.4 before 22.4R3-S6-EVO
affected

23.2 before 23.2R2-S3-EVO
affected

23.4 before 23.4R2-S4-EVO
affected

24.2 before 24.2R2-EVO
affected

References

supportportal.juniper.net/JSA100066 vendor-advisory

cve.org (CVE-2025-52958)

nvd.nist.gov (CVE-2025-52958)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-52958

Support options

Helpdesk Chat, Email, Knowledgebase