CVE-2025-52958

MEDIUM

Juniper Junos < 22.2 - Reachable Assertion

Title source: rule
STIX 2.1

Description

A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS).On all Junos OS and Junos OS Evolved devices, when route validation is enabled, a rare condition during BGP initial session establishment can lead to an rpd crash and restart. This occurs specifically when the connection request fails during error-handling scenario. Continued session establishment failures leads to a sustained DoS condition.  This issue affects Junos OS: * All versions before 22.2R3-S6, * from 22.4 before 22.4R3-S6, * from 23.2 before 23.2R2-S3, * from 23.4 before 23.4R2-S4, * from 24.2 before 24.2R2; Junos OS Evolved: * All versions before 22.2R3-S6-EVO, * from 22.4 before 22.4R3-S6-EVO, * from 23.2 before 23.2R2-S3-EVO, * from 23.4 before 23.4R2-S4-EVO, * from 24.2 before 24.2R2-EVO.

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 4.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-617
Status published
Products (7)
juniper/junos 22.2 (13 CPE variants)
juniper/junos 22.4 (13 CPE variants)
juniper/junos 23.2 (7 CPE variants)
juniper/junos 23.4 (8 CPE variants)
juniper/junos 24.2 (4 CPE variants)
juniper/junos < 22.2
juniper/junos_os_evolved 22.2 (4 CPE variants)
Published Jul 11, 2025
Tracked Since Feb 18, 2026