CVE-2025-52958 Information

Description

A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS).On all Junos OS and Junos OS Evolved devices when route validation is enabled a rare condition during BGP initial session establishment can lead to an rpd crash and restart. This occurs specifically when the connection request fails during error-handling scenario.

Continued session establishment failures leads to a sustained DoS condition. 

This issue affects Junos OS:

All versions before 22.2R3-S6 
from 22.4 before 22.4R3-S6 
from 23.2 before 23.2R2-S3 
from 23.4 before 23.4R2-S4 
from 24.2 before 24.2R2; 

Junos OS Evolved: All versions before 22.2R3-S6-EVO from 22.4 before 22.4R3-S6-EVO from 23.2 before 23.2R2-S3-EVO from 23.4 before 23.4R2-S4-EVO from 24.2 before 24.2R2-EVO.

CVSS Vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Reference

https://supportportal.juniper.net/JSA100066

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

5.3

CNNVD-202507-1660 (Published: 2025-07-11)

Share on: