Use of Incorrect Operator Vulnerability in Juniper Networks Junos OS Evolved Firewall
CVE-2025-52985
6.9MEDIUM
What is CVE-2025-52985?
A vulnerability exists within the Routing Engine firewall of Juniper Networks' Junos OS Evolved that can allow an unauthenticated network attacker to bypass security restrictions. Specifically, when a firewall filter applied to the lo0 or re:mgmt interface references a prefix list with 'from prefix-list', the filter fails to match if the list exceeds 10 entries. This flaw affects both IPv4 and IPv6 traffic, allowing packets to evade filtering under certain configurations, posing significant security risks.
Affected Version(s)
Junos OS Evolved 23.2R2-S3-EVO < 23.2R2-S4-EVO
Junos OS Evolved 23.4R2-S3-EVO < 23.4R2-S5-EVO
Junos OS Evolved 24.2R2-EVO < 24.2R2-S1-EVO