Denial-of-Service Vulnerability in Junos OS Routing Protocol Daemon
CVE-2025-21593
6.5MEDIUM
Summary
A Denial-of-Service vulnerability exists in the routing protocol daemon (rpd) of Juniper Networks' Junos OS and Junos OS Evolved. This vulnerability permits an unauthenticated network attacker to disrupt service by sending malformed BGP UPDATE packets, particularly when Segment Routing over IPv6 (SRv6) is enabled. Such packets can trigger the rpd to crash and restart repeatedly, leading to a persistent Denial-of-Service condition that affects both iBGP and eBGP for IPv4 and IPv6. The issue impacts multiple versions of the Junos OS and Junos OS Evolved, necessitating immediate attention to safeguard network operations.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published