CVE-2025-59962
EUVD-2025-3339809.10.2025, 16:15
An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved with BGP sharding configured allows an attacker triggering indirect next-hop updates, along with timing outside the attacker's control, to cause rpd to crash and restart, leading to a Denial of Service (DoS). With BGP sharding enabled, triggering route resolution of an indirect next-hop (e.g., an IGP route change over which a BGP route gets resolved), may cause rpd to crash and restart. An attacker causing continuous IGP route churn, resulting in repeated route re-resolution, will increase the likelihood of triggering this issue, leading to a potentially extended DoS condition. This issue affects: Junos OS: * all versions before 21.4R3-S6, * from 22.1 before 22.1R3-S6, * from 22.2 before 22.2R3-S3, * from 22.3 before 22.3R3-S3, * from 22.4 before 22.4R3, * from 23.2 before 23.2R2; Junos OS Evolved: * all versions before 22.3R3-S3-EVO, * from 22.4 before 22.4R3-EVO, * from 23.2 before 23.2R2-EVO. Versions before Junos OS 21.3R1 and Junos OS Evolved 21.3R1-EVO are unaffected by this issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| juniper | junos | 𝑥 < 21.4 |
| juniper | junos | 21.4 |
| juniper | junos | 21.4:r1 |
| juniper | junos | 21.4:r1-s1 |
| juniper | junos | 21.4:r1-s2 |
| juniper | junos | 21.4:r2 |
| juniper | junos | 21.4:r2-s1 |
| juniper | junos | 21.4:r2-s2 |
| juniper | junos | 21.4:r3 |
| juniper | junos | 21.4:r3-s1 |
| juniper | junos | 21.4:r3-s2 |
| juniper | junos | 21.4:r3-s3 |
| juniper | junos | 21.4:r3-s4 |
| juniper | junos | 21.4:r3-s5 |
| juniper | junos | 22.1 |
| juniper | junos | 22.1:r1 |
| juniper | junos | 22.1:r1-s1 |
| juniper | junos | 22.1:r1-s2 |
| juniper | junos | 22.1:r2 |
| juniper | junos | 22.1:r2-s1 |
| juniper | junos | 22.1:r2-s2 |
| juniper | junos | 22.1:r3 |
| juniper | junos | 22.1:r3-s1 |
| juniper | junos | 22.1:r3-s2 |
| juniper | junos | 22.1:r3-s3 |
| juniper | junos | 22.1:r3-s4 |
| juniper | junos | 22.1:r3-s5 |
| juniper | junos | 22.2 |
| juniper | junos | 22.2:r1 |
| juniper | junos | 22.2:r1-s1 |
| juniper | junos | 22.2:r1-s2 |
| juniper | junos | 22.2:r2 |
| juniper | junos | 22.2:r2-s1 |
| juniper | junos | 22.2:r2-s2 |
| juniper | junos | 22.2:r3 |
| juniper | junos | 22.2:r3-s1 |
| juniper | junos | 22.2:r3-s2 |
| juniper | junos | 22.3 |
| juniper | junos | 22.3:r1 |
| juniper | junos | 22.3:r1-s1 |
| juniper | junos | 22.3:r1-s2 |
| juniper | junos | 22.3:r2 |
| juniper | junos | 22.3:r2-s1 |
| juniper | junos | 22.3:r2-s2 |
| juniper | junos | 22.3:r3 |
| juniper | junos | 22.3:r3-s1 |
| juniper | junos | 22.3:r3-s2 |
| juniper | junos | 22.4 |
| juniper | junos | 22.4:r1 |
| juniper | junos | 22.4:r1-s1 |
| juniper | junos | 22.4:r1-s2 |
| juniper | junos | 22.4:r2 |
| juniper | junos | 22.4:r2-s1 |
| juniper | junos | 22.4:r2-s2 |
| juniper | junos | 23.2 |
| juniper | junos | 23.2:r1 |
| juniper | junos | 23.2:r1-s1 |
| juniper | junos | 23.2:r1-s2 |
| juniper | junos_os_evolved | 𝑥 < 22.3 |
| juniper | junos_os_evolved | 22.3 |
| juniper | junos_os_evolved | 22.3:r1 |
| juniper | junos_os_evolved | 22.3:r1-s1 |
| juniper | junos_os_evolved | 22.3:r1-s2 |
| juniper | junos_os_evolved | 22.3:r2 |
| juniper | junos_os_evolved | 22.3:r2-s1 |
| juniper | junos_os_evolved | 22.3:r2-s2 |
| juniper | junos_os_evolved | 22.3:r3 |
| juniper | junos_os_evolved | 22.3:r3-s1 |
| juniper | junos_os_evolved | 22.3:r3-s2 |
| juniper | junos_os_evolved | 22.4 |
| juniper | junos_os_evolved | 22.4:r1 |
| juniper | junos_os_evolved | 22.4:r1-s1 |
| juniper | junos_os_evolved | 22.4:r1-s2 |
| juniper | junos_os_evolved | 22.4:r2 |
| juniper | junos_os_evolved | 22.4:r2-s1 |
| juniper | junos_os_evolved | 22.4:r2-s2 |
| juniper | junos_os_evolved | 23.2 |
| juniper | junos_os_evolved | 23.2:r1 |
| juniper | junos_os_evolved | 23.2:r1-s1 |
| juniper | junos_os_evolved | 23.2:r1-s2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration