Password Aging Vulnerability in Juniper Networks Junos OS and Junos OS Evolved
CVE-2025-60010

5.3MEDIUM

Key Information:

Vendor
CVE Published:
9 October 2025

Badges

👾 Exploit Exists

What is CVE-2025-60010?

A security issue in the RADIUS client of Juniper Networks' Junos OS and Junos OS Evolved allows authenticated network-based attackers to bypass mandatory password change policies. Due to this vulnerability, users whose passwords have expired may still log in if the RADIUS server responds with a reject without enforcing the required password change, creating a potential access point for unauthorized activity. This affects various versions of Junos OS and Junos OS Evolved, especially under certain conditions of RADIUS password management, and necessitates prompt action to mitigate security risks by updating to the latest versions.

Affected Version(s)

Junos OS 0 < 22.4R3-S8

Junos OS 23.2 < 23.2R2-S4

Junos OS 23.4 < 23.4R2-S5

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-60010 : Password Aging Vulnerability in Juniper Networks Junos OS and Junos OS Evolved