Denial of Service Vulnerability in Juniper Networks Junos OS on SRX4700 Devices
CVE-2025-59964

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
9 October 2025

Badges

👾 Exploit Exists

What is CVE-2025-59964?

A vulnerability exists in the Packet Forwarding Engine (PFE) of Juniper Networks' Junos OS which can be exploited by an unauthenticated, network-based attacker. When the forwarding-options sampling feature is enabled, certain traffic directed to the Routing Engine (RE) can result in a crash and restart of the Flexible PIC Concentrator (FPC). This leads to a Denial of Service (DoS) condition, which can be prolonged by continuous reception of traffic targeting the RE. This issue affects both IPv4 and IPv6 traffic, impacting device availability significantly.

Affected Version(s)

Junos OS SRX4700 24.4 < 24.4R1-S3, 24.4R2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59964 : Denial of Service Vulnerability in Juniper Networks Junos OS on SRX4700 Devices